← Back

Mariadb

mariadb

418 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Mariadb
mariadb
Connector/c
connector/c
Maxscale
maxscale

CVEs (418)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Juniper
MariadbOracle
4Junos Space
MariadbMysql+1 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a differe...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.Show less
2Mariadb
Oracle
2Mariadb
Mysql
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:DML.
4Juniper
MariadbOracle+1 more
8Junos Space
Linux Enterprise DesktopLinux Enterprise Server+5 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.
3Mariadb
OracleSuse
7Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+4 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB DML FOREIGN KEYS.
3Mariadb
OracleSuse
7Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+4 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
3.3 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS.
2Mariadb
Oracle
3Mariadb
MysqlSolaris
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.1 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to SERVER:MyISAM.
4Debian
MariadbOracle+1 more
8Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+5 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
6Debian
MariadbOpensuse Project+3 more
12Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+9 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors relat...Show more
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.Show less
3Mariadb
OracleSuse
6Linux Enterprise Desktop
Linux Enterprise ServerLinux Enterprise Software Development Kit+3 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
2.8 LOW· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED.
4Debian
MariadbOracle+1 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+4 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.
4Debian
MariadbOracle+1 more
7Debian Linux
Linux Enterprise DesktopLinux Enterprise Server+4 more
May 6, 2026
Jul 17, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.
6Fedoraproject
MariadbOpenssl+3 more
11Enterprise Linux
FedoraLeap+8 more
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of s...Show more
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.Show less
9Fedoraproject
Filezilla ProjectMariadb+6 more
16Application Processing Engine Firmware
Cp1543 1 FirmwareEnterprise Linux+13 more
May 6, 2026
Jun 5, 2014
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key...Show more
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.Show less
6Fedoraproject
MariadbOpenssl+3 more
11Enterprise Linux
FedoraLeap+8 more
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS he...Show more
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.Show less
4Fedoraproject
MariadbOpenssl+1 more
5Fedora
LeapMariadb+2 more
May 6, 2026
Jun 5, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote at...Show more
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.Show less
6Debian
FedoraprojectMariadb+3 more
9Debian Linux
FedoraLinux Enterprise Desktop+6 more
May 6, 2026
May 6, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to c...Show more
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.Show less