Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
MySQL Comunity Edition Number Of NVD 1286 CRITICAL 7 HIGH 76 MEDIUM 1021 LOW 173
URL https://www.mysql.com/jp/products/community/
Explanation It is an open source, free relational database management system (RDBMS) that is used around the world.
Its performance and functionality are sufficient for commercial use, and it is used for more than just the backend of web applications.
With the merger of Sun Microsystems into Oracle, it was feared that it might no longer be available for free commercial use, but it is still available under the GPL license for cloud backend and internal use.
It is still used as a backend for many web applications (WordPress, Facebook, etc.).

Since it has been merged with Oracle, the development speed has been increased, and the latest version is a higher performance, higher functionality relational database management system (RDBMS).

You can also get technical support by paying a support fee.

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).
Tag
  • GPL v2
  • オープンソース
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://dev.mysql.com/downloads/mysql/
2 https://endoflife.software/applications/databases/mysql

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1271 MySQL 8.1 8.1.0 July 18, 2023 July 18, 2023 0 0 0 0
1272 New!! MySQL 8 8.0.45 Jan. 20, 2029 April 19, 2018 April 19, 2026 4 25 565 54
1273 MySQL 5.7 5.7.44 Oct. 25, 2023 Jan. 21, 2015 Oct. 21, 2023 6 26 356 33
1274 MySQL 5.6 5.6.51 Jan. 20, 2021 Feb. 5, 2013 Feb. 5, 2021 5 28 359 90
1275 MySQL 5.5 5.5.62 Oct. 22, 2018 Oct. 3, 2010 Jan. 3, 2018 3 26 347 92
1276 MySQL 7.6 7.6.9 Jan. 1, 2000 0 2 40 16
1277 MySQL 7.5 7.5.9 Jan. 1, 2000 0 2 39 15
1278 MySQL 7.4 7.4.9 Jan. 1, 2000 0 2 38 14
1279 MySQL 7.3 7.3.9 Jan. 1, 2000 0 2 13 0
1280 MySQL 7.2 7.2.35 Jan. 1, 2000 0 0 12 0
1281 MySQL 7.1 7.1.37 Jan. 1, 2000 0 0 12 0
1282 MySQL 6.0 6.0.5 Jan. 1, 2000 0 0 18 1
1283 MySQL 5.4 5.4.3 Jan. 1, 2000 0 3 132 41
1284 MySQL 5.3 5.3.9 Jan. 1, 2000 0 3 133 41
1285 MySQL 5.1 5.1.9 Dec. 31, 2013 0 10 221 60
1286 MySQL 5.0 5.0.96 Jan. 9, 2012 0 8 168 54
1287 MySQL 4.1 4.1.9 Jan. 1, 2000 0 5 136 47
1288 MySQL 4.0 4.0.9 Jan. 1, 2000 0 11 139 48
1289 MySQL 3.2 3.20.32a Jan. 1, 2000 0 10 128 45
1290 MySQL 1.5 1.5.1 Jan. 1, 2000 0 6 127 44
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1271 -
7.5
HIGH The default configuration in MySQL 3.20.32 through 3.23.52, when running on Windows, does not have logging enabled, which could allow remote attackers to conduct activities without detection. NVD-CWE-Other
CVE-2002-1923 cpe:2.3:a:oracle:mysql:3.23.9:*
cpe:2.3:a:oracle:mysql:3.23.8:*
cpe:2.3:a:oracle:mysql:3.23.5:*
cpe:2.3:a:orac…
2019-10-8 01:40
2002-12-31
Show GitHub Exploit DB Packet Storm
1272 -
5.0
MEDIUM Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL 3.23.x before 3.23.54 allows remote attackers to cause a denial of service (crash or hang) in mysqld by causing large negative int… NVD-CWE-Other
CVE-2002-1373 cpe:2.3:a:oracle:mysql:4.0.5a:*
cpe:2.3:a:oracle:mysql:4.0.3:*
cpe:2.3:a:oracle:mysql:4.0.2:*
cpe:2.3:a:oracle…
2019-10-8 01:41
2002-12-23
Show GitHub Exploit DB Packet Storm
1273 -
7.5
HIGH The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL t… NVD-CWE-Other
CVE-2002-1374 cpe:2.3:a:oracle:mysql:4.0.5a:*
cpe:2.3:a:oracle:mysql:4.0.3:*
cpe:2.3:a:oracle:mysql:4.0.2:*
cpe:2.3:a:oracle…
2019-10-8 01:41
2002-12-23
Show GitHub Exploit DB Packet Storm
1274 -
7.5
HIGH The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response. NVD-CWE-Other
CVE-2002-1375 cpe:2.3:a:oracle:mysql:4.0.5a:*
cpe:2.3:a:oracle:mysql:4.0.3:*
cpe:2.3:a:oracle:mysql:4.0.2:*
cpe:2.3:a:oracle…
2019-10-8 01:41
2002-12-23
Show GitHub Exploit DB Packet Storm
1275 -
7.5
HIGH libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows r… NVD-CWE-Other
CVE-2002-1376 cpe:2.3:a:oracle:mysql:4.0.5a:*
cpe:2.3:a:oracle:mysql:4.0.3:*
cpe:2.3:a:oracle:mysql:4.0.2:*
cpe:2.3:a:oracle…
2019-10-8 01:41
2002-12-23
Show GitHub Exploit DB Packet Storm
1276 7.8
4.6
HIGH
Local
Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary code via a long "datadir" parameter in the my.ini ini… CWE-120
Classic Buffer Overflow
CVE-2002-0969 cpe:2.3:a:oracle:mysql:*:*
4.0.0

4.0.2

3.23.50
2024-01-27 02:19
2002-10-11
Show GitHub Exploit DB Packet Storm
1277 -
4.6
MEDIUM WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database. NVD-CWE-Other
CVE-2001-1255 cpe:2.3:a:oracle:mysql:3.23:* 2019-10-8 01:38
2001-10-2
Show GitHub Exploit DB Packet Storm
1278 -
4.6
MEDIUM Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot). NVD-CWE-Other
CVE-2001-0407 cpe:2.3:a:oracle:mysql:*:* 3.23.36 2019-10-8 01:40
2001-06-27
Show GitHub Exploit DB Packet Storm
1279 -
7.5
HIGH Buffer overflow in libmysqlclient.so in MySQL 3.23.33 and earlier allows remote attackers to execute arbitrary code via a long host parameter. NVD-CWE-Other
CVE-2001-1453 cpe:2.3:a:oracle:mysql:3.23.32:* 2019-10-8 01:40
2001-02-9
Show GitHub Exploit DB Packet Storm
1280 -
7.5
HIGH Buffer overflow in MySQL before 3.23.33 allows remote attackers to execute arbitrary code via a long drop database request. NVD-CWE-Other
CVE-2001-1454 cpe:2.3:a:oracle:mysql:*:* 3.23.32 2019-10-8 01:40
2001-02-9
Show GitHub Exploit DB Packet Storm