Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
MySQL Comunity Edition Number Of NVD 1286 CRITICAL 7 HIGH 76 MEDIUM 1021 LOW 173
URL https://www.mysql.com/jp/products/community/
Explanation It is an open source, free relational database management system (RDBMS) that is used around the world.
Its performance and functionality are sufficient for commercial use, and it is used for more than just the backend of web applications.
With the merger of Sun Microsystems into Oracle, it was feared that it might no longer be available for free commercial use, but it is still available under the GPL license for cloud backend and internal use.
It is still used as a backend for many web applications (WordPress, Facebook, etc.).

Since it has been merged with Oracle, the development speed has been increased, and the latest version is a higher performance, higher functionality relational database management system (RDBMS).

You can also get technical support by paying a support fee.

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • GPL v2
  • オープンソース
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://dev.mysql.com/downloads/mysql/
2 https://endoflife.software/applications/databases/mysql

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1261 MySQL 8.1 8.1.0 July 18, 2023 July 18, 2023 0 0 0 0
1262 New!! MySQL 8 8.0.45 Jan. 20, 2029 April 19, 2018 April 19, 2026 4 25 565 54
1263 MySQL 5.7 5.7.44 Oct. 25, 2023 Jan. 21, 2015 Oct. 21, 2023 6 26 356 33
1264 MySQL 5.6 5.6.51 Jan. 20, 2021 Feb. 5, 2013 Feb. 5, 2021 5 28 359 90
1265 MySQL 5.5 5.5.62 Oct. 22, 2018 Oct. 3, 2010 Jan. 3, 2018 3 26 347 92
1266 MySQL 7.6 7.6.9 Jan. 1, 2000 0 2 40 16
1267 MySQL 7.5 7.5.9 Jan. 1, 2000 0 2 39 15
1268 MySQL 7.4 7.4.9 Jan. 1, 2000 0 2 38 14
1269 MySQL 7.3 7.3.9 Jan. 1, 2000 0 2 13 0
1270 MySQL 7.2 7.2.35 Jan. 1, 2000 0 0 12 0
1271 MySQL 7.1 7.1.37 Jan. 1, 2000 0 0 12 0
1272 MySQL 6.0 6.0.5 Jan. 1, 2000 0 0 18 1
1273 MySQL 5.4 5.4.3 Jan. 1, 2000 0 3 132 41
1274 MySQL 5.3 5.3.9 Jan. 1, 2000 0 3 133 41
1275 MySQL 5.1 5.1.9 Dec. 31, 2013 0 10 221 60
1276 MySQL 5.0 5.0.96 Jan. 9, 2012 0 8 168 54
1277 MySQL 4.1 4.1.9 Jan. 1, 2000 0 5 136 47
1278 MySQL 4.0 4.0.9 Jan. 1, 2000 0 11 139 48
1279 MySQL 3.2 3.20.32a Jan. 1, 2000 0 10 128 45
1280 MySQL 1.5 1.5.1 Jan. 1, 2000 0 6 127 44
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1261 -
4.6
MEDIUM The mysqlhotcopy script in mysql 4.0.20 and earlier, when using the scp method from the mysql-server package, allows local users to overwrite arbitrary files via a symlink attack on temporary files. NVD-CWE-Other
CVE-2004-0457 cpe:2.3:a:oracle:mysql:*:* 4.0.20 2019-12-18 02:11
2004-09-28
Show GitHub Exploit DB Packet Storm
1262 -
2.1
LOW The mysqld_multi script in MySQL allows local users to overwrite arbitrary files via a symlink attack. NVD-CWE-Other
CVE-2004-0388 cpe:2.3:a:oracle:mysql:5.0.33:* 2019-12-18 02:14
2004-06-1
Show GitHub Exploit DB Packet Storm
1263 -
2.1
LOW mysqlbug in MySQL allows local users to overwrite arbitrary files via a symlink attack on the failed-mysql-bugreport temporary file. NVD-CWE-Other
CVE-2004-0381 cpe:2.3:a:oracle:mysql:4.1.0:alpha
cpe:2.3:a:oracle:mysql:4.0.9:gamma
cpe:2.3:a:oracle:mysql:4.0.9:*
cpe:2.3:a…
2019-12-18 02:11
2004-05-4
Show GitHub Exploit DB Packet Storm
1264 -
4.0
MEDIUM Stack-based buffer overflow in the mysql_real_connect function in the MySql client library (libmysqlclient) 4.0.13 and earlier allows local users to execute arbitrary code via a long socket name, a d… NVD-CWE-Other
CVE-2003-1331 cpe:2.3:a:oracle:mysql:*:gamma 4.0.9 2019-10-8 01:42
2003-12-31
Show GitHub Exploit DB Packet Storm
1265 -
4.3
MEDIUM MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods. CWE-310
Cryptographic Issues
CVE-2003-1480 cpe:2.3:a:oracle:mysql:4.1.0:alpha
cpe:2.3:a:oracle:mysql:4.0.9:gamma
cpe:2.3:a:oracle:mysql:4.0.8:gamma
cpe:2…
2019-12-18 02:11
2003-12-31
Show GitHub Exploit DB Packet Storm
1266 -
9.0
HIGH Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privileges to execute arbitrary code via a long Password field. NVD-CWE-Other
CVE-2003-0780 cpe:2.3:a:oracle:mysql:4.1.0:alpha
cpe:2.3:a:oracle:mysql:4.0.9:gamma
cpe:2.3:a:oracle:mysql:4.0.9:*
cpe:2.3:a…
2019-12-18 02:11
2003-09-22
Show GitHub Exploit DB Packet Storm
1267 -
9.0
HIGH MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql … NVD-CWE-Other
CVE-2003-0150 cpe:2.3:a:oracle:mysql:3.23.55:*
cpe:2.3:a:oracle:mysql:3.23.54a:*
cpe:2.3:a:oracle:mysql:3.23.54:*
cpe:2.3:a:…
2019-10-8 01:41
2003-03-24
Show GitHub Exploit DB Packet Storm
1268 -
5.0
MEDIUM Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user. NVD-CWE-Other
CVE-2003-0073 cpe:2.3:a:oracle:mysql:3.23.54a:*
cpe:2.3:a:oracle:mysql:3.23.54:*
cpe:2.3:a:oracle:mysql:3.23.53:*
cpe:2.3:a:…
2019-10-8 01:41
2003-02-19
Show GitHub Exploit DB Packet Storm
1269 -
7.5
HIGH The default configuration of the Windows binary release of MySQL 3.23.2 through 3.23.52 has a NULL root password, which could allow remote attackers to gain unauthorized root access to the MySQL data… NVD-CWE-Other
CVE-2002-1809 cpe:2.3:a:oracle:mysql:3.23.9:*
cpe:2.3:a:oracle:mysql:3.23.8:*
cpe:2.3:a:oracle:mysql:3.23.5:*
cpe:2.3:a:orac…
2019-10-8 01:40
2002-12-31
Show GitHub Exploit DB Packet Storm
1270 -
7.5
HIGH The default configuration of MySQL 3.20.32 through 3.23.52, when running on Windows, does set the bind address to the loopback interface, which allows remote attackers to connect to the database. NVD-CWE-Other
CVE-2002-1921 cpe:2.3:a:oracle:mysql:3.23.9:*
cpe:2.3:a:oracle:mysql:3.23.8:*
cpe:2.3:a:oracle:mysql:3.23.5:*
cpe:2.3:a:orac…
2019-10-8 01:40
2002-12-31
Show GitHub Exploit DB Packet Storm