Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

191 – 200 of 216 results


CVE-2022-27384

Medium priority

Some fixes available 3 of 6

An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27383

Medium priority

Some fixes available 3 of 6

MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27382

Medium priority

Some fixes available 3 of 6

MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27381

Medium priority

Some fixes available 3 of 6

An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27380

Medium priority

Some fixes available 3 of 6

An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27379

Medium priority

Some fixes available 3 of 6

An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27378

Medium priority

Some fixes available 3 of 6

An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27377

Medium priority

Some fixes available 3 of 6

MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2022-27376

Medium priority

Some fixes available 3 of 6

MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

6 affected packages

mariadb-10.0, mariadb-10.1, mariadb-10.3, mariadb-10.5, mariadb-10.6, mariadb-5.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
mariadb-10.0 Needs evaluation
mariadb-10.1 Needs evaluation Ignored
mariadb-10.3 Fixed Ignored
mariadb-10.5 Ignored
mariadb-10.6 Not in release Fixed Ignored
mariadb-5.5 Ignored
Show less packages

CVE-2018-25032

Medium priority
Fixed

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

5 affected packages

klibc, mariadb-10.3, mariadb-10.6, rsync, zlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
klibc Fixed Fixed Fixed Fixed Fixed
mariadb-10.3 Not in release Fixed Not in release Ignored
mariadb-10.6 Not in release Fixed Not in release Not in release Ignored
rsync Not affected Not affected Fixed Fixed Fixed
zlib Fixed Fixed Fixed Fixed Fixed
Show less packages