Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
MySQL Comunity Edition Number Of NVD 1286 CRITICAL 7 HIGH 76 MEDIUM 1021 LOW 173
URL https://www.mysql.com/jp/products/community/
Explanation It is an open source, free relational database management system (RDBMS) that is used around the world.
Its performance and functionality are sufficient for commercial use, and it is used for more than just the backend of web applications.
With the merger of Sun Microsystems into Oracle, it was feared that it might no longer be available for free commercial use, but it is still available under the GPL license for cloud backend and internal use.
It is still used as a backend for many web applications (WordPress, Facebook, etc.).

Since it has been merged with Oracle, the development speed has been increased, and the latest version is a higher performance, higher functionality relational database management system (RDBMS).

You can also get technical support by paying a support fee.

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • GPL v2
  • オープンソース
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://dev.mysql.com/downloads/mysql/
2 https://endoflife.software/applications/databases/mysql

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1231 MySQL 8.1 8.1.0 July 18, 2023 July 18, 2023 0 0 0 0
1232 New!! MySQL 8 8.0.45 Jan. 20, 2029 April 19, 2018 April 19, 2026 4 25 565 54
1233 MySQL 5.7 5.7.44 Oct. 25, 2023 Jan. 21, 2015 Oct. 21, 2023 6 26 356 33
1234 MySQL 5.6 5.6.51 Jan. 20, 2021 Feb. 5, 2013 Feb. 5, 2021 5 28 359 90
1235 MySQL 5.5 5.5.62 Oct. 22, 2018 Oct. 3, 2010 Jan. 3, 2018 3 26 347 92
1236 MySQL 7.6 7.6.9 Jan. 1, 2000 0 2 40 16
1237 MySQL 7.5 7.5.9 Jan. 1, 2000 0 2 39 15
1238 MySQL 7.4 7.4.9 Jan. 1, 2000 0 2 38 14
1239 MySQL 7.3 7.3.9 Jan. 1, 2000 0 2 13 0
1240 MySQL 7.2 7.2.35 Jan. 1, 2000 0 0 12 0
1241 MySQL 7.1 7.1.37 Jan. 1, 2000 0 0 12 0
1242 MySQL 6.0 6.0.5 Jan. 1, 2000 0 0 18 1
1243 MySQL 5.4 5.4.3 Jan. 1, 2000 0 3 132 41
1244 MySQL 5.3 5.3.9 Jan. 1, 2000 0 3 133 41
1245 MySQL 5.1 5.1.9 Dec. 31, 2013 0 10 221 60
1246 MySQL 5.0 5.0.96 Jan. 9, 2012 0 8 168 54
1247 MySQL 4.1 4.1.9 Jan. 1, 2000 0 5 136 47
1248 MySQL 4.0 4.0.9 Jan. 1, 2000 0 11 139 48
1249 MySQL 3.2 3.20.32a Jan. 1, 2000 0 10 128 45
1250 MySQL 1.5 1.5.1 Jan. 1, 2000 0 6 127 44
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1231 -
3.5
LOW MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement. NVD-CWE-Other
CVE-2007-2693 cpe:2.3:a:oracle:mysql:5.1.9:*
cpe:2.3:a:oracle:mysql:5.1.6:*
cpe:2.3:a:oracle:mysql:5.1.17:*
cpe:2.3:a:oracle…
2026-04-23 09:35
2007-05-16
Show GitHub Exploit DB Packet Storm
1232 -
4.0
MEDIUM The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause tha… NVD-CWE-noinfo
CVE-2007-2583 cpe:2.3:a:oracle:mysql:*:*
5.1

5.1.17

5.0.40
2026-04-23 09:35
2007-05-10
Show GitHub Exploit DB Packet Storm
1233 -
2.1
LOW MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which preven… NVD-CWE-Other
CVE-2007-1420 cpe:2.3:a:oracle:mysql:5.0.7:*
cpe:2.3:a:oracle:mysql:5.0.6:*
cpe:2.3:a:oracle:mysql:5.0.41:*
cpe:2.3:a:oracle…
2026-04-23 09:35
2007-03-13
Show GitHub Exploit DB Packet Storm
1234 -
3.6
LOW MySQL before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs … NVD-CWE-Other
CVE-2006-4226 cpe:2.3:a:oracle:mysql:5.1.9:*
cpe:2.3:a:oracle:mysql:5.1.8:*
cpe:2.3:a:oracle:mysql:5.1.7:*
cpe:2.3:a:oracle:…
2019-12-18 05:16
2006-08-19
Show GitHub Exploit DB Packet Storm
1235 -
6.5
MEDIUM MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated user… CWE-20
 Improper Input Validation 
CVE-2006-4227 cpe:2.3:a:oracle:mysql:5.1.9:*
cpe:2.3:a:oracle:mysql:5.1.6:*
cpe:2.3:a:oracle:mysql:5.1.10:*
cpe:2.3:a:oracle…
2019-12-18 05:05
2006-08-19
Show GitHub Exploit DB Packet Storm
1236 -
2.1
LOW MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, whic… NVD-CWE-Other
CVE-2006-4031 cpe:2.3:a:oracle:mysql:5.0.9:*
cpe:2.3:a:oracle:mysql:5.0.8:*
cpe:2.3:a:oracle:mysql:5.0.7:*
cpe:2.3:a:oracle:…
2019-12-18 05:16
2006-08-10
Show GitHub Exploit DB Packet Storm
1237 -
4.0
MEDIUM Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead… CWE-134
Use of Externally-Controlled Format String
CVE-2006-3469 cpe:2.3:a:oracle:mysql:5.0.9:*
cpe:2.3:a:oracle:mysql:5.0.6:*
cpe:2.3:a:oracle:mysql:5.0.19:*
cpe:2.3:a:oracle…
2019-12-18 05:16
2006-07-21
Show GitHub Exploit DB Packet Storm
1238 -
2.1
LOW Off-by-one buffer overflow in the Instance_options::complete_initialization function in instance_options.cc in the Instance Manager in MySQL before 5.0.23 and 5.1 before 5.1.12 might allow local user… CWE-189
Numeric Errors
CVE-2006-3486 cpe:2.3:a:oracle:mysql:5.1.9:*
cpe:2.3:a:oracle:mysql:5.1.8:*
cpe:2.3:a:oracle:mysql:5.1.7:*
cpe:2.3:a:oracle:…
2024-08-8 04:15
2006-07-11
Show GitHub Exploit DB Packet Storm
1239 -
4.0
MEDIUM mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date func… NVD-CWE-Other
CVE-2006-3081 cpe:2.3:a:oracle:mysql:5.0.18:*
cpe:2.3:a:oracle:mysql:4.1.7:*
cpe:2.3:a:oracle:mysql:4.1.5:*
cpe:2.3:a:oracle…
2019-12-18 02:13
2006-06-20
Show GitHub Exploit DB Packet Storm
1240 -
7.5
HIGH SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to execute arbitrary SQL commands via crafted multibyte encodings in character sets… NVD-CWE-Other
CVE-2006-2753 cpe:2.3:a:oracle:mysql:5.0.9:*
cpe:2.3:a:oracle:mysql:5.0.8:*
cpe:2.3:a:oracle:mysql:5.0.7:*
cpe:2.3:a:oracle:…
2019-12-18 05:16
2006-06-2
Show GitHub Exploit DB Packet Storm