← Back

Mariadb

mariadb

Vendor: Mariadb • 406 CVEs

CVEs (406)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Mariadb
Oracle
2Mariadb
Mysql
Apr 29, 2026
Jan 22, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote a...Show more
Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7, and 5.5.x through 5.5.25, allow remote authenticated users to execute arbitrary SQL commands via vectors related to the binary log. NOTE: as of 20130116, Oracle has not commented on claims from a downstream vendor that the fix in MySQL 5.5.29 is incomplete.Show less
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Stored Procedure.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.6 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows local users to affect confidentiality and integrity via unknown vectors related to Server Replication.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Information Schema.
4Canonical
MariadbOracle+1 more
7Enterprise Linux
Enterprise Linux DesktopEnterprise Linux Eus+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote attackers to affect availability via unknown vectors related to Server Locking.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Serve...Show more
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.1.28 and earlier, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Server Replication.Show less
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability, related to MyISAM.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Partition.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.65 and earlier and 5.5.27 and earlier allows remote authenticated users to affect availability, related to GIS Extension.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote attackers to affect availability via unknown vectors.
3Canonical
MariadbOracle
3Mariadb
MysqlUbuntu Linux
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors.
4Canonical
MariadbOracle+1 more
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB.
2Mariadb
Oracle
2Mariadb
Mysql
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user nam...Show more
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.Show less
3Mariadb
OracleRedhat
7Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+4 more
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXM...Show more
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.Show less
2Mariadb
Oracle
2Mariadb
Mysql
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated...Show more
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging the FILE privilege to create files as the MySQL administrator. NOTE: the vendor disputes this issue, stating that this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: it could be argued that this should not be included in CVE because it is a configuration issue.Show less