VulnerabilityModified
CVE-2015-0433
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
MEDIUM 4.0EPSS 5.38%
Does this matter?
Lower severity and a low EPSS score (5.38%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 5.38% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- oracle/communications policy management · oracle/mysql · oracle/solaris · debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · suse/linux enterprise desktop · suse/linux enterprise server · suse/linux enterprise software development kit · mariadb/mariadb
- Source
- secalert_us@oracle.com
References
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1628.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1629.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3229Third Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlVendor Advisory
- http://www.securitytracker.com/id/1032121Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2575-1Third Party Advisory
- https://security.gentoo.org/glsa/201507-19Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1628.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1629.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1647.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-1665.htmlThird Party Advisory
- http://www.debian.org/security/2015/dsa-3229Third Party Advisory
- http://www.debian.org/security/2015/dsa-3311Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlPatch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.htmlVendor Advisory
- http://www.securitytracker.com/id/1032121Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2575-1Third Party Advisory
- https://security.gentoo.org/glsa/201507-19Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.