CVEs (23)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3. |
ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. |
1Clickhouse 2Clickhouse Clickhouse CloudDec 23, 2025 Mar 18, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 ClickHouse is an open-source column-oriented database management system. A bug exists in the cloud ClickHouse offering prior to version 24.0.2.54535 and in github.com/clickhouse/clickhouse version 23.1. Query caching byp...Show more |
1Clickhouse 2Clickhouse Clickhouse CloudNov 21, 2024 Dec 22, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 ClickHouse is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could sen...Show more |
1Clickhouse 2Clickhouse Clickhouse CloudNov 21, 2024 Dec 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. This vulnerability is an integer underflow resulting in crash due to stack buffer over...Show more |
1Clickhouse 2Clickhouse Clickhouse CloudNov 21, 2024 Dec 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could se...Show more |
An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could cause a heap buffer overflow and crash the server by inserting a malformed CapnProto object. The fixed...Show more |
An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endpoint (usually listening on port 8123 by default), causing a heap-based buffer overflow that crashes...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that the copy operations in the LZ4::decompressImpl loop and especially the arbitrary copy operation wil...Show more |
Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. |
Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. |
Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data....Show more |
2Clickhouse Debian2Clickhouse Debian LinuxJun 25, 2025 Mar 14, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data....Show more |
In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol. |
In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the network where ClickHouse runs, can create a custom-built malicious serv...Show more |
ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. |
In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. |
In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability. |