4
CVSSv2

CVE-2009-0819

Published: 05/03/2009 Updated: 17/12/2019
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

sql/item_xmlfunc.cc in MySQL 5.1 prior to 5.1.32 and 6.0 prior to 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql 5.1.30

mysql mysql

oracle mysql 5.1.23

mysql mysql 5.1.23

oracle mysql 5.1.2

oracle mysql 5.1.16

oracle mysql 5.1.15

oracle mysql 6.0.4

oracle mysql 6.0.3

oracle mysql 5.1.14

oracle mysql 5.1.11

oracle mysql 5.1.1

oracle mysql 5.1.21

oracle mysql 5.1.29

oracle mysql 5.1.26

oracle mysql 5.1.18

oracle mysql 5.1.19

oracle mysql 5.1.24

oracle mysql 5.1.25

mysql mysql 6.0.9

mysql mysql 6.0.10-bzr

oracle mysql 6.0.0

mysql mysql 5.1.31

oracle mysql 5.1.12

oracle mysql 5.1.17

oracle mysql 5.1.22

oracle mysql 5.1.27

oracle mysql 5.1.31

oracle mysql 6.0.2

oracle mysql 6.0.1

oracle mysql 5.1.3

oracle mysql 5.1.13

oracle mysql 5.1.10

oracle mysql 5.1

oracle mysql 5.1.20

oracle mysql 5.1.28

Exploits

source: wwwsecurityfocuscom/bid/33972/info MySQL is prone to a remote denial-of-service vulnerability because it fails to handle certain XPath expressions An attacker can exploit this issue to crash the application, denying access to legitimate users This issue affects: MySQL 5131 and earlier MySQL 609 and earlier select updatex ...