MySQL 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。
過去の問題は主に vendor risk sql injection and vendor risk cross-site scripting などに関し、一部は vendor impact unexpected behavior を招き、vendor surface data access and vendor surface data storage 関連の場面に影響します。
掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2017-15945 | The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages before 2017-09-29 have chown calls for user-writable directory trees, which allows local users to gain privileges by leveraging access to the mysql account for creation of a link. | [email protected] | 7.8 | 0.37% | 2017-10-27 | 2026-05-13 |
| CVE-2015-2575 | Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J. | [email protected] | 4.9 | 3.59% | 2015-04-16 | 2026-05-06 |
| CVE-2013-1492 | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553. | [email protected] | 7.5 | 2.83% | 2013-03-28 | 2026-04-29 |
| CVE-2012-0553 | Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492. | [email protected] | 7.5 | 2.60% | 2013-03-28 | 2026-04-29 |
| CVE-2012-0882 | Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VulnDisco Pack Professional 9.17. NOTE: as of 20120224, this disclosure has no actionable information. However, because the module author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. NOTE: due to lack of details, it is not | [email protected] | 7.5 | 5.30% | 2012-12-21 | 2026-04-29 |
| CVE-2012-2749 | MySQL 5.1.x before 5.1.63 and 5.5.x before 5.5.24 allows remote authenticated users to cause a denial of service (mysqld crash) via vectors related to incorrect calculation and a sort order index. | [email protected] | 4.0 | 1.90% | 2012-08-17 | 2026-04-29 |
| CVE-2012-2102 | MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT. | [email protected] | 3.5 | 2.09% | 2012-08-17 | 2026-04-29 |
| CVE-2009-5026 | The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments. | [email protected] | 6.8 | 7.76% | 2012-08-17 | 2026-04-29 |
| CVE-2012-1696 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | [email protected] | 4.0 | 1.96% | 2012-05-03 | 2026-04-29 |
| CVE-2012-0583 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM. | [email protected] | 4.0 | 1.84% | 2012-05-03 | 2026-04-29 |
| CVE-2012-0492 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0485. | [email protected] | 2.1 | 2.60% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0490 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect availability via unknown vectors. | [email protected] | 4.0 | 3.01% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0485 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0120, and CVE-2012-0492. | [email protected] | 4.0 | 3.01% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0484 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows remote authenticated users to affect confidentiality via unknown vectors. | [email protected] | 4.0 | 2.67% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0120 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0119, CVE-2012-0485, and CVE-2012-0492. | [email protected] | 4.0 | 2.58% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0119 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492. | [email protected] | 4.0 | 2.58% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0118 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and availability via unknown vectors, a different vulnerability than CVE-2012-0113. | [email protected] | 4.9 | 2.19% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0116 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | [email protected] | 4.9 | 2.01% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0115 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0119, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492. | [email protected] | 4.0 | 2.58% | 2012-01-18 | 2026-04-29 |
| CVE-2012-0114 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x, 5.1.x, and 5.5.x allows local users to affect confidentiality and integrity via unknown vectors. | [email protected] | 3.0 | 0.36% | 2012-01-18 | 2026-04-29 |