Page 36 of 361 results (0.007 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 1

11 Oct 2002 — Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group. Desbordamiento de búfer en MySQL anteriores a 3.23.50, y 4.0 beta anteriores a 4.02 sobre Windows, y posiblemente otras plataformas, permite a usuarios locales ejecutar código arbitrario mediante un parámetro datadir largo e... • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0004.html • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

02 Oct 2001 — WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database. • http://online.securityfocus.com/archive/1/217848 •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 2

27 Jun 2001 — Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot). • https://www.exploit-db.com/exploits/20718 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

09 Feb 2001 — Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request. • http://dev.mysql.com/doc/mysql/en/news-3-23-33.html •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 1

09 Feb 2001 — Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter. • http://dev.mysql.com/doc/mysql/en/news-3-23-33.html •

CVSS: 9.8EPSS: 1%CPEs: 1EXPL: 1

23 Jan 2001 — Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges. • https://www.exploit-db.com/exploits/20581 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

19 Jan 2001 — MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. • http://marc.info/?l=bugtraq&m=98089552030459&w=2 •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

19 Dec 2000 — MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password. • http://archives.neohapsis.com/archives/bugtraq/2000-10/0318.html •

CVSS: 9.8EPSS: 0%CPEs: 7EXPL: 0

08 Feb 2000 — MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string. • http://archives.neohapsis.com/archives/bugtraq/2000-02/0053.html •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 1

11 Jan 2000 — MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege. • https://www.exploit-db.com/exploits/19721 •