CVE-2002-0969
https://notcve.org/view.php?id=CVE-2002-0969
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini initialization file, whose permissions on Windows allow Full Control to the Everyone group. Desbordamiento de búfer en MySQL anteriores a 3.23.50, y 4.0 beta anteriores a 4.02 sobre Windows, y posiblemente otras plataformas, permite a usuarios locales ejecutar código arbitrario mediante un parámetro datadir largo en el fichero de inicialización my.ini, cuyos permisos en Windows permiten Control Total al grupo Todos. • http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0004.html http://marc.info/?l=bugtraq&m=103358628011935&w=2 http://www.iss.net/security_center/static/10243.php http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.x http://www.securityfocus.com/bid/5853 http://www.westpoint.ltd.uk/advisories/wp-02-0003.txt • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •
CVE-2001-0407 – MySQL 3.20.32 a/3.23.34 - Root Operation Symbolic Link File Overwriting
https://notcve.org/view.php?id=CVE-2001-0407
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot). • https://www.exploit-db.com/exploits/20718 http://archives.neohapsis.com/archives/bugtraq/2001-03/0237.html http://archives.neohapsis.com/archives/bugtraq/2001-03/0396.html http://www.securityfocus.com/bid/2522 https://exchange.xforce.ibmcloud.com/vulnerabilities/6617 •
CVE-2001-1454
https://notcve.org/view.php?id=CVE-2001-1454
Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request. • http://dev.mysql.com/doc/mysql/en/news-3-23-33.html http://www.kb.cert.org/vuls/id/367320 http://www.securityfocus.com/archive/1/161917 https://exchange.xforce.ibmcloud.com/vulnerabilities/6419 •
CVE-2001-1274 – Mysql 3.22.x/3.23.x - Local Buffer Overflow
https://notcve.org/view.php?id=CVE-2001-1274
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges. • https://www.exploit-db.com/exploits/20581 http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000375 http://marc.info/?l=bugtraq&m=98089552030459&w=2 http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt http://www.debian.org/security/2001/dsa-013 http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3 http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.3 http://www.redhat.com/support/errata/RHSA-2001 •
CVE-2001-1275
https://notcve.org/view.php?id=CVE-2001-1275
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking. • http://marc.info/?l=bugtraq&m=98089552030459&w=2 http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3 http://www.redhat.com/support/errata/RHSA-2001-003.html •