Vulnerabilities (CVE)

Filtered by vendor Oracle Subscribe
Filtered by product Mysql
Total 1328 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2001-1275 1 Oracle 1 Mysql 2026-06-16 7.2 HIGH N/A
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.
CVE-2001-1274 1 Oracle 1 Mysql 2026-06-16 7.5 HIGH N/A
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.
CVE-2001-1255 2 Mysql, Oracle 2 Winmysqladmin, Mysql 2026-06-16 4.6 MEDIUM N/A
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.
CVE-2001-0407 1 Oracle 1 Mysql 2026-06-16 4.6 MEDIUM N/A
Directory traversal vulnerability in MySQL before 3.23.36 allows local users to modify arbitrary files and gain privileges by creating a database whose name starts with .. (dot dot).
CVE-2000-0981 1 Oracle 1 Mysql 2026-06-16 7.2 HIGH N/A
MySQL Database Engine uses a weak authentication method which leaks information that could be used by a remote attacker to recover the password.
CVE-2000-0148 1 Oracle 1 Mysql 2026-06-16 7.5 HIGH N/A
MySQL 3.22 allows remote attackers to bypass password authentication and access a database via a short check string.
CVE-2000-0045 1 Oracle 1 Mysql 2026-06-16 6.4 MEDIUM N/A
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
CVE-1999-1188 1 Oracle 1 Mysql 2026-06-16 4.6 MEDIUM N/A
mysqld in MySQL 3.21 creates log files with world-readable permissions, which allows local users to obtain passwords for users who are added to the user database.