Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 572 respecto a la semana anterior
Críticas / altas1455▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1973 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 29% | 💥 Exploit | MysqlOracle Mysql | 21/7/2006 | 16/6/2026 | Vulnerabilidad de cadena de formato en time.cc de MySQL Server 4.1 anterior a 4.1.21 y 5.0 anterior al 1 de abril de 2006 permite a usuarios autenticados remotamente provocar una denegación de servicio (caída) mediante una cadena de formato en lugar de una fecha como el primer parámetro para la función date_format, la… | |
| Modificada | Baja (2.1) | 0.65% | — | MysqlOracle Mysql | 10/7/2006 | 16/6/2026 | ** IMPUGNADA ** Desbordamiento de búfer por superación del límite en la función Instance_options::complete_initialization de instance_options.cc en el Instance Manager de MySQL antes de 5.0.23 y 5.1 antes de 5.1.12 podría permitir a usuarios locales provocar una denegación de servicio (caída de aplicación) mediante… | |
| Modificada | Media (4) | 26% | 💥 Exploit | MysqlOracle Mysql | 19/6/2006 | 16/6/2026 | mysqld en MySQL v4.1.x antes de v4.1.18, v5.0.x antes de v5.0.19, y v5.1.x antes de v5.1.6 permite causar una denegación de servicio (caída del demonio) a usuarios remotos autorizados a través de un segundo argumento nulo para la función STR_TO_DATE. | |
| Modificada | Alta (7.5) | 3.5% | — | MysqlOracle Mysql | 1/6/2006 | 16/6/2026 | SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets such as SJIS, BIG5, and GBK, which are not properly handled when the mysql_real_escape function is used to escape the… | |
| Modificada | Media (6.5) | 38% | 💥 Exploit | MysqlOracle Mysql | 5/5/2006 | 16/6/2026 | Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values. | |
| Modificada | Media (5) | 5.0% | — | MysqlOracle Mysql | 5/5/2006 | 16/6/2026 | sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to obtain sensitive information via a COM_TABLE_DUMP request with an incorrect packet length, which includes portions of memory in an error message. | |
| Modificada | Media (5) | 36% | 💥 Exploit | MysqlOracle Mysql | 5/5/2006 | 16/6/2026 | The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Media (4.3) | 1.2% | — | Cholod Mysql Based Message Board | 26/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Cholod MySQL Based Message Board allow remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (4.6) | 1.4% | 💥 Exploit | MysqlOracle Mysql | 27/2/2006 | 16/6/2026 | MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null… | |
| Modificada | Alta (7.5) | 1.4% | — | Carey Briggs PHP Mysql Timesheet | 15/2/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Carey Briggs PHP/MYSQL Timesheet 1 and 2 allow remote attackers to execute arbitrary SQL commands via the (1) yr, (2) month, (3) day, and (4) job parameters in (a) index.php and (b) changehrs.php. | |
| Modificada | Alta (7.5) | 6.3% | — | Pam-mysql | 13/2/2006 | 16/6/2026 | Double free vulnerability in the authentication and authentication token alteration code in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted passwords, which lead to a double free of a pointer… | |
| Modificada | Baja (2.1) | 0.80% | — | Oracle Mysql | 22/1/2006 | 16/6/2026 | MySQL 5.0.18 allows local users with access to a VIEW to obtain sensitive information via the "SELECT * FROM information_schema.views;" query, which returns the query that created the VIEW. NOTE: this issue has been disputed by third parties, saying that the availability of the schema is a normal and sometimes desired… | |
| Modificada | Media (5.8) | 2.9% | 💥 Exploit | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to view.php, (2) release parameter to list.php, or (3) F parameter to get_jsrs_data.php. | |
| Modificada | Media (5) | 1.9% | — | PAM Mysql | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in the SQL logging facility in PAM-MySQL 0.6.x before 0.6.2 and 0.7.x before 0.7pre3 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors, probably involving the pam_mysql_sql_log function when being used in vsftpd, which does not include the IP… | |
| Modificada | Media (6.4) | 2.0% | 💥 Exploit | Mysql Eventum | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in MySQL Eventum 1.5.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) isCorrectPassword or (2) userExist function in class.auth.php, getCustomFieldReport function in (4) custom_fields.php, (5) custom_fields_graph.php, or (6) class.report.php, or… | |
| Modificada | Media (4.3) | 1.2% | — | Servers-r-us Mysqlauction | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MySQL Auction 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters, possibly the keyword parameter in the SearchZoom module. | |
| Modificada | Alta (8.5) | 4.7% | — | Oracle Mysql | 16/8/2005 | 16/6/2026 | MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a… | |
| Modificada | Media (4.6) | 2.3% | — | MysqlOracle Mysql | 16/8/2005 | 16/6/2026 | Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field. | |
| Modificada | Media (5) | 2.8% | — | MysqlOracle Mysql | 16/8/2005 | 16/6/2026 | The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character. | |
| Modificada | Baja (2.1) | 0.33% | — | Xmysqladmin | 9/6/2005 | 16/6/2026 | xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp. | |
| Modificada | Media (4.6) | 0.61% | — | MysqlOracle Mysql | 17/5/2005 | 16/6/2026 | mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents. | |
| Modificada | Media (4.6) | 18% | 💥 Exploit | MysqlOracle Mysql | 2/5/2005 | 16/6/2026 | MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary code by using CREATE FUNCTION to access libc calls, as demonstrated by using strcat, on_exit, and exit. | |
| Modificada | Baja (2.1) | 1.7% | 💥 Exploit | MysqlOracle Mysql | 2/5/2005 | 16/6/2026 | MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack. | |
| Modificada | Media (4.6) | 13% | 💥 Exploit | MysqlOracle Mysql | 2/5/2005 | 16/6/2026 | MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function. |