// For flags

CVE-2006-1516

MySQL 4.1.18/5.0.20 - Local/Remote Information Leakage

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-03-30 CVE Reserved
  • 2006-05-02 First Exploit
  • 2006-05-05 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-24 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
References (45)
URL Tag Source
http://bugs.debian.org/365938 X_refsource_confirm
http://docs.info.apple.com/article.html?artnum=305214 X_refsource_confirm
http://secunia.com/advisories/20002 Third Party Advisory
http://secunia.com/advisories/20073 Third Party Advisory
http://secunia.com/advisories/20076 Third Party Advisory
http://secunia.com/advisories/20223 Third Party Advisory
http://secunia.com/advisories/20241 Third Party Advisory
http://secunia.com/advisories/20253 Third Party Advisory
http://secunia.com/advisories/20333 Third Party Advisory
http://secunia.com/advisories/20424 Third Party Advisory
http://secunia.com/advisories/20457 Third Party Advisory
http://secunia.com/advisories/20625 Third Party Advisory
http://secunia.com/advisories/20762 Third Party Advisory
http://secunia.com/advisories/24479 Third Party Advisory
http://secunia.com/advisories/29847 Third Party Advisory
http://securityreason.com/securityalert/840 Third Party Advisory
http://www.securityfocus.com/archive/1/432733/100/0/threaded Mailing List
http://www.securityfocus.com/archive/1/434164/100/0/threaded Mailing List
http://www.securityfocus.com/bid/17780 Vdb Entry
http://www.us-cert.gov/cas/techalerts/TA07-072A.html Third Party Advisory
http://www.vupen.com/english/advisories/2006/1633 Vdb Entry
http://www.vupen.com/english/advisories/2007/0930 Vdb Entry
http://www.vupen.com/english/advisories/2008/1326/references Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/26236 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9918 Signature
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.0
Search vendor "Mysql" for product "Mysql" and version "4.1.0"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.3
Search vendor "Mysql" for product "Mysql" and version "4.1.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.8
Search vendor "Mysql" for product "Mysql" and version "4.1.8"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.10
Search vendor "Mysql" for product "Mysql" and version "4.1.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.12
Search vendor "Mysql" for product "Mysql" and version "4.1.12"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.13
Search vendor "Mysql" for product "Mysql" and version "4.1.13"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.14
Search vendor "Mysql" for product "Mysql" and version "4.1.14"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
4.1.15
Search vendor "Mysql" for product "Mysql" and version "4.1.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.1
Search vendor "Mysql" for product "Mysql" and version "5.0.1"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.2
Search vendor "Mysql" for product "Mysql" and version "5.0.2"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.3
Search vendor "Mysql" for product "Mysql" and version "5.0.3"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.4
Search vendor "Mysql" for product "Mysql" and version "5.0.4"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.5
Search vendor "Mysql" for product "Mysql" and version "5.0.5"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.10
Search vendor "Mysql" for product "Mysql" and version "5.0.10"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.15
Search vendor "Mysql" for product "Mysql" and version "5.0.15"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.16
Search vendor "Mysql" for product "Mysql" and version "5.0.16"
-
Affected
Mysql
Search vendor "Mysql"
Mysql
Search vendor "Mysql" for product "Mysql"
5.0.17
Search vendor "Mysql" for product "Mysql" and version "5.0.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.0
Search vendor "Oracle" for product "Mysql" and version "4.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.1
Search vendor "Oracle" for product "Mysql" and version "4.0.1"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.2
Search vendor "Oracle" for product "Mysql" and version "4.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.3
Search vendor "Oracle" for product "Mysql" and version "4.0.3"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.4
Search vendor "Oracle" for product "Mysql" and version "4.0.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.5
Search vendor "Oracle" for product "Mysql" and version "4.0.5"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.5a
Search vendor "Oracle" for product "Mysql" and version "4.0.5a"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.6
Search vendor "Oracle" for product "Mysql" and version "4.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.7
Search vendor "Oracle" for product "Mysql" and version "4.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.7
Search vendor "Oracle" for product "Mysql" and version "4.0.7"
gamma
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.8
Search vendor "Oracle" for product "Mysql" and version "4.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.8
Search vendor "Oracle" for product "Mysql" and version "4.0.8"
gamma
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.9
Search vendor "Oracle" for product "Mysql" and version "4.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.9
Search vendor "Oracle" for product "Mysql" and version "4.0.9"
gamma
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.10
Search vendor "Oracle" for product "Mysql" and version "4.0.10"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.11
Search vendor "Oracle" for product "Mysql" and version "4.0.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.11
Search vendor "Oracle" for product "Mysql" and version "4.0.11"
gamma
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.12
Search vendor "Oracle" for product "Mysql" and version "4.0.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.13
Search vendor "Oracle" for product "Mysql" and version "4.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.14
Search vendor "Oracle" for product "Mysql" and version "4.0.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.15
Search vendor "Oracle" for product "Mysql" and version "4.0.15"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.16
Search vendor "Oracle" for product "Mysql" and version "4.0.16"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.17
Search vendor "Oracle" for product "Mysql" and version "4.0.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.18
Search vendor "Oracle" for product "Mysql" and version "4.0.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.19
Search vendor "Oracle" for product "Mysql" and version "4.0.19"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.20
Search vendor "Oracle" for product "Mysql" and version "4.0.20"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.21
Search vendor "Oracle" for product "Mysql" and version "4.0.21"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.23
Search vendor "Oracle" for product "Mysql" and version "4.0.23"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.24
Search vendor "Oracle" for product "Mysql" and version "4.0.24"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.25
Search vendor "Oracle" for product "Mysql" and version "4.0.25"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.0.26
Search vendor "Oracle" for product "Mysql" and version "4.0.26"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.0
Search vendor "Oracle" for product "Mysql" and version "4.1.0"
alpha
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.2
Search vendor "Oracle" for product "Mysql" and version "4.1.2"
alpha
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.3
Search vendor "Oracle" for product "Mysql" and version "4.1.3"
beta
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.4
Search vendor "Oracle" for product "Mysql" and version "4.1.4"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.5
Search vendor "Oracle" for product "Mysql" and version "4.1.5"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.6
Search vendor "Oracle" for product "Mysql" and version "4.1.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.7
Search vendor "Oracle" for product "Mysql" and version "4.1.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.9
Search vendor "Oracle" for product "Mysql" and version "4.1.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.11
Search vendor "Oracle" for product "Mysql" and version "4.1.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.16
Search vendor "Oracle" for product "Mysql" and version "4.1.16"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.17
Search vendor "Oracle" for product "Mysql" and version "4.1.17"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
4.1.18
Search vendor "Oracle" for product "Mysql" and version "4.1.18"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.0
Search vendor "Oracle" for product "Mysql" and version "5.0.0"
alpha
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.3
Search vendor "Oracle" for product "Mysql" and version "5.0.3"
beta
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.6
Search vendor "Oracle" for product "Mysql" and version "5.0.6"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.7
Search vendor "Oracle" for product "Mysql" and version "5.0.7"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.8
Search vendor "Oracle" for product "Mysql" and version "5.0.8"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.9
Search vendor "Oracle" for product "Mysql" and version "5.0.9"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.11
Search vendor "Oracle" for product "Mysql" and version "5.0.11"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.12
Search vendor "Oracle" for product "Mysql" and version "5.0.12"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.13
Search vendor "Oracle" for product "Mysql" and version "5.0.13"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.14
Search vendor "Oracle" for product "Mysql" and version "5.0.14"
-
Affected
Oracle
Search vendor "Oracle"
Mysql
Search vendor "Oracle" for product "Mysql"
5.0.18
Search vendor "Oracle" for product "Mysql" and version "5.0.18"
-
Affected