CVE-2005-0083
MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3)…
Does this matter?
Lower severity and a low EPSS score (1.41%). Track it; it rarely justifies an emergency change on its own.
Description
MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 1.41% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- mysql/maxdb
- Source
- cve@mitre.org
References
- http://www.idefense.com/application/poi/display?id=218&type=vulnerabilitiesPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19687
- http://www.idefense.com/application/poi/display?id=218&type=vulnerabilitiesPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19687
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.