VulnerabilityModified
CVE-2014-0437
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
LOW 3.5EPSS 3.21%
Does this matter?
Lower severity and a low EPSS score (3.21%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
- EPSS
- 3.21% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- oracle/mysql · debian/debian linux · canonical/ubuntu linux · mariadb/mariadb · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- secalert_us@oracle.com
References
- http://osvdb.org/102074Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-0164.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0173.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0186.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0189.htmlThird Party Advisory
- http://secunia.com/advisories/56491Not Applicable
- http://secunia.com/advisories/56541Not Applicable
- http://secunia.com/advisories/56580Not Applicable
- http://security.gentoo.org/glsa/glsa-201409-04.xmlThird Party Advisory
- http://ubuntu.com/usn/usn-2086-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2845Third Party Advisory
- http://www.debian.org/security/2014/dsa-2848Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlVendor Advisory
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/64849Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90385Third Party Advisory, VDB Entry
- http://osvdb.org/102074Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-0164.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0173.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0186.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0189.htmlThird Party Advisory
- http://secunia.com/advisories/56491Not Applicable
- http://secunia.com/advisories/56541Not Applicable
- http://secunia.com/advisories/56580Not Applicable
- http://security.gentoo.org/glsa/glsa-201409-04.xmlThird Party Advisory
- http://ubuntu.com/usn/usn-2086-1Third Party Advisory
- http://www.debian.org/security/2014/dsa-2845Third Party Advisory
- http://www.debian.org/security/2014/dsa-2848Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.htmlVendor Advisory
- http://www.securityfocus.com/bid/64758Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.