VulnerabilityModified
CVE-2014-4260
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
MEDIUM 5.5EPSS 3.48%
Does this matter?
Lower severity and a low EPSS score (3.48%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
- EPSS
- 3.48% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- oracle/mysql · oracle/solaris · debian/debian linux · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · suse/linux enterprise workstation extension · mariadb/mariadb
- Source
- secalert_us@oracle.com
References
- http://lists.opensuse.org/opensuse-security-announce/2014-08/msg00012.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/60425Not Applicable
- http://www.debian.org/security/2014/dsa-2985Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/68573Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030578Broken Link, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94621Third Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2014-08/msg00012.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2014/Dec/23Mailing List, Third Party Advisory
- http://secunia.com/advisories/60425Not Applicable
- http://www.debian.org/security/2014/dsa-2985Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/534161/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/68573Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1030578Broken Link, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2014-0012.htmlThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94621Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.