VulnerabilityModified
CVE-2014-0386
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
MEDIUM 4.0EPSS 3.36%
Does this matter?
Lower severity and a low EPSS score (3.36%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.71 and earlier, 5.5.33 and earlier, and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 3.36% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- oracle/mysql · mariadb/mariadb · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- secalert_us@oracle.com
References
- http://osvdb.org/102069Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-0164.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0173.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0186.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0189.htmlThird Party Advisory
- http://secunia.com/advisories/56491Not Applicable
- http://secunia.com/advisories/56541Not Applicable
- http://secunia.com/advisories/56580Not Applicable
- http://security.gentoo.org/glsa/glsa-201409-04.xmlThird Party Advisory
- http://ubuntu.com/usn/usn-2086-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2845Third Party Advisory
- http://www.debian.org/security/2014/dsa-2848Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlVendor Advisory
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64904Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90380Third Party Advisory, VDB Entry
- http://osvdb.org/102069Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-0164.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0173.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0186.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0189.htmlThird Party Advisory
- http://secunia.com/advisories/56491Not Applicable
- http://secunia.com/advisories/56541Not Applicable
- http://secunia.com/advisories/56580Not Applicable
- http://security.gentoo.org/glsa/glsa-201409-04.xmlThird Party Advisory
- http://ubuntu.com/usn/usn-2086-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2845Third Party Advisory
- http://www.debian.org/security/2014/dsa-2848Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlVendor Advisory
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.