VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 16 hours ago
Reset
More filters (1)
Columns
Oracle product: Oracle MySQL / Server: Logging
Overview 6 matches · 0 in RASP scope · 0 protected · 0 KEV · 1 public PoC · 0 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
6matches 0in RASP scope0.0% 0protected0.0% 0KEV0.0% 1public PoC16.7% 0CISA SSVC0.0% 1EPSS ≥ 0.516.7% 0disputed0.0%
Critical 1 16.7% High 0 0.0% Medium 4 66.7% Low 1 16.7% None 0 0.0% Unknown 0 0.0%
Protected by RASP 0 0.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 3 50.0% Out of RASP scope 3 50.0% Rejected 0 0.0%
blocked by ARMR today 0 0.0% not blocked 6 100.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 16.7% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 5 83.3%
split by peak 1 / quarter
Unknown: 0None: 0Low: 1Medium: 4High: 0Critical: 1 Rejected: 0Out of RASP scope: 3Not applicable: 3Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 0 unrecorded: 0not established: 0not blocked: 6blocked by ARMR today: 0 No public exploit: 5Forecast only: 0Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 Q3 2016: 1 CVE Q4 2016: 0 CVEs Q1 2017: 0 CVEs Q2 2017: 0 CVEs Q3 2017: 0 CVEs Q4 2017: 0 CVEs Q1 2018: 0 CVEs Q2 2018: 0 CVEs Q3 2018: 0 CVEs Q4 2018: 1 CVE Q1 2019: 0 CVEs Q2 2019: 0 CVEs Q3 2019: 0 CVEs Q4 2019: 0 CVEs Q1 2020: 0 CVEs Q2 2020: 1 CVE Q3 2020: 0 CVEs Q4 2020: 1 CVE Q1 2021: 0 CVEs Q2 2021: 0 CVEs Q3 2021: 0 CVEs Q4 2021: 1 CVE Q1 2022: 0 CVEs Q2 2022: 1 CVE
Q4 16Q2 17Q4 17Q2 18Q4 18Q2 19Q4 19Q2 20Q4 20Q2 21Q4 21Q2 22
6 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2022-21460 Medium 2022-04-19 Out of RASP scope No public exploit Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
CVE-2021-35633 Low 2021-10-20 Not applicable No public exploit Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).
CVE-2020-14873 Medium 2020-10-21 Not applicable No public exploit Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2020-2770 Medium 2020-04-15 Out of RASP scope No public exploit Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2018-3283 Medium 2018-10-17 Out of RASP scope No public exploit Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
CVE-2016-6662 Critical 2016-09-20 Not applicable Working exploit published Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.