6.8
CVSSv3

CVE-2016-8318

Published: 27/01/2017 Updated: 07/03/2019
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 4 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:P

Vulnerability Summary

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption). Supported versions that are affected are 5.6.34 and previous versions and 5.7.16 and previous versions. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 6.8 (Availability impacts).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql

Vendor Advisories

Several security issues were fixed in MySQL ...
Debian Bug report logs - #851234 Security fixes from the January 2017 CPU Package: src:mysql-56; Maintainer for src:mysql-56 is (unknown); Reported by: "Norvald H Ryeng" <norvaldryeng@oraclecom> Date: Fri, 13 Jan 2017 08:24:04 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in versions mysql-56/5 ...
Debian Bug report logs - #851235 Security fixes from the January 2017 CPU Package: src:mysql-57; Maintainer for src:mysql-57 is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: "Norvald H Ryeng" <norvaldryeng@oraclecom> Date: Fri, 13 Jan 2017 08:24:07 UTC Severity: grave Tags: fix ...
The following security-related issues were fixed: CVE-2016-8318 Server: Security: Encryption unspecified vulnerabilityCVE-2016-8327 Server: Replication unspecified vulnerabilityCVE-2017-3238 Server: Optimizer unspecified vulnerabilityCVE-2017-3244 Server: DML unspecified vulnerabilityCVE-2017-3257 Server: InnoDB unspecified vulnerabilityCVE-2017-32 ...
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption) Supported versions that are affected are 5634 and earlier and 5716 and earlier Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server Successful attacks requir ...