Pingcap
Pingcap Tidb: vulnerabilidades y CVE
Pingcap Tidb tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-41433 | Crítica (9.8) | 0.57% | — | 3 sept 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE:… |
| CVE-2024-41434 | Media (4.3) | 0.41% | — | 3 sept 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it… |
| CVE-2024-37820 | Media (5.4) | 0.38% | — | 25 jun 2024 | A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation. |
| CVE-2024-35618 | Alta (7.5) | 0.41% | — | 24 may 2024 | PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer. |
| CVE-2024-33809 | Media (6.5) | 0.43% | — | 24 may 2024 | PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks. |
| CVE-2022-3023 | Crítica (9.8) | 0.61% | — | 4 nov 2022 | Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. |
| CVE-2022-34969 | Alta (7.5) | 0.90% | — | 3 ago 2022 | PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference. |
| CVE-2022-31011 | Alta (7.8) | 0.32% | — | 31 may 2022 | TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the… |