Pingcap
Pingcap Tidb: vulnerabilities and CVEs
Pingcap Tidb has 8 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41433 | Critical (9.8) | 0.57% | — | Sep 3, 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE:… |
| CVE-2024-41434 | Medium (4.3) | 0.41% | — | Sep 3, 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it… |
| CVE-2024-37820 | Medium (5.4) | 0.38% | — | Jun 25, 2024 | A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation. |
| CVE-2024-35618 | High (7.5) | 0.41% | — | May 24, 2024 | PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer. |
| CVE-2024-33809 | Medium (6.5) | 0.43% | — | May 24, 2024 | PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks. |
| CVE-2022-3023 | Critical (9.8) | 0.61% | — | Nov 4, 2022 | Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. |
| CVE-2022-34969 | High (7.5) | 0.90% | — | Aug 3, 2022 | PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference. |
| CVE-2022-31011 | High (7.8) | 0.32% | — | May 31, 2022 | TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Under certain conditions, an attacker can construct malicious authentication requests to bypass the… |