
CVE-2022-27384 – mariadb: crash via component Item_subselect::init_expr_cache_tracker
https://notcve.org/view.php?id=CVE-2022-27384
12 Apr 2022 — An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. Se ha detectado un problema en el componente Item_subselect::init_expr_cache_tracker de MariaDB Server versiones v10.6 y anteriores, que permite a atacantes causar una Denegación de Servicio (DoS) por medio de sentencias SQL especialmente diseñadas A flaw was found in MariaDB. An issue in the component, ... • https://jira.mariadb.org/browse/MDEV-26047 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-27382 – mariadb: assertion failure via component Item_field::used_tables/update_depend_map_for_order
https://notcve.org/view.php?id=CVE-2022-27382
12 Apr 2022 — MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order. Se ha detectado que MariaDB Server versiones v10.7 y anteriores, contienen un fallo de segmentación por medio del componente Item_field::used_tables/update_depend_map_for_order A flaw was found in MariaDB. A segmentation fault via the component, Item_field::used_tables/update_depend_map_for_order, impacts availability. MariaDB is a multi-user, multi-threaded SQ... • https://jira.mariadb.org/browse/MDEV-26402 • CWE-617: Reachable Assertion •

CVE-2022-27383 – mariadb: use-after-poison in my_strcasecmp_8bit() of ctype-simple.c
https://notcve.org/view.php?id=CVE-2022-27383
12 Apr 2022 — MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements. Se ha detectado que MariaDB Server versiones v10.6 y anteriores, contienen un uso de memoria previamente liberada en el componente my_strcasecmp_8bit, que es explotada por medio de sentencias SQL especialmente diseñadas A flaw was found in the MariaDB Server. A use-after-free in the component, my_strcasecmp_8bit, can be exploited via special... • https://jira.mariadb.org/browse/MDEV-26323 • CWE-416: Use After Free •

CVE-2022-27380 – mariadb: server crash at my_decimal::operator=
https://notcve.org/view.php?id=CVE-2022-27380
12 Apr 2022 — An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. Se ha detectado un problema en el componente my_decimal::operator= de MariaDB Server versiones v10.6.3 y anteriores, que permite a atacantes causar una denegación de servicio (DoS) por medio de sentencias SQL especialmente diseñadas A flaw was found in MariaDB. The component, my_decimal::operator=, allows attackers to c... • https://jira.mariadb.org/browse/MDEV-26280 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-27381 – mariadb: server crash at Field::set_default via specially crafted SQL statements
https://notcve.org/view.php?id=CVE-2022-27381
12 Apr 2022 — An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. Se ha detectado un problema en el componente Field::set_default de MariaDB Server versiones v10.6 y anteriores, que permite a atacantes causar una denegación de servicio (DoS) por medio de sentencias SQL especialmente diseñadas A flaw was found in MariaDB. The component, Field::set_default, allows attackers to cause a denial... • https://jira.mariadb.org/browse/MDEV-26061 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-27378 – mariadb: server crash in create_tmp_table::finalize
https://notcve.org/view.php?id=CVE-2022-27378
12 Apr 2022 — An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. Se ha detectado un problema en el componente Create_tmp_table::finalize de MariaDB Server versiones v10.7 y anteriores, que permite a atacantes causar una denegación de servicio (DoS) por medio de sentencias SQL especialmente diseñadas A flaw was found in MariaDB. The component, Create_tmp_table::finalize, allows att... • https://jira.mariadb.org/browse/MDEV-26423 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-27379 – mariadb: server crash in component arg_comparator::compare_real_fixed
https://notcve.org/view.php?id=CVE-2022-27379
12 Apr 2022 — An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. Se ha detectado un problema en el componente Arg_comparator::compare_real_fixed de MariaDB Server versiones v10.6.2 y anteriores, que permite a atacantes causar una Denegación de Servicio (DoS) por medio de sentencias SQL especialmente diseñadas A flaw was found in MariaDB. The component, Arg_comparator::co... • https://jira.mariadb.org/browse/MDEV-26353 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2022-27377 – mariadb: use-after-poison when complex conversion is involved in blob
https://notcve.org/view.php?id=CVE-2022-27377
12 Apr 2022 — MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements. Se ha detectado que MariaDB Server versiones v10.6.3 y anteriores, contienen un uso de memoria previamente liberada en el componente Item_func_in::cleanup(), que es explotada por medio de sentencias SQL especialmente diseñadas A flaw was found in the MariaDB Server, where it contains a use-after-free in the component, Item_func_in::cl... • https://jira.mariadb.org/browse/MDEV-26281 • CWE-416: Use After Free •

CVE-2022-27376 – mariadb: assertion failure in Item_args::walk_arg
https://notcve.org/view.php?id=CVE-2022-27376
12 Apr 2022 — MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements. Se ha detectado que MariaDB Server versiones v10.6.5 y anteriores, contienen un uso de memoria previamente liberada en el componente Item_args::walk_arg, que es explotada por medio de sentencias SQL especialmente diseñadas A use-after-free flaw was found in Maria DB. The MariaDB Server contains a use-after-free in the component, Item_args... • https://jira.mariadb.org/browse/MDEV-26354 • CWE-416: Use After Free CWE-617: Reachable Assertion •

CVE-2018-25032 – zlib: A flaw found in zlib when compressing (not decompressing) certain inputs
https://notcve.org/view.php?id=CVE-2018-25032
25 Mar 2022 — zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. zlib versiones anteriores a 1.2.12 permite la corrupción de memoria al desinflar (es decir, al comprimir) si la entrada tiene muchas coincidencias distantes An out-of-bounds access flaw was found in zlib, which allows memory corruption when deflating (ex: when compressing) if the input has many distant matches. For some rare inputs with a large number of distant matches (crafted payload... • https://github.com/Trinadh465/external_zlib_4.4_CVE-2018-25032 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-787: Out-of-bounds Write •