187
VMScore

CVE-2021-46657

Published: 29/01/2022 Updated: 12/07/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

get_sort_by_table in MariaDB prior to 10.6.2 allows an application crash via certain subquery uses of ORDER BY.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mariadb mariadb

Vendor Advisories

Synopsis Moderate: mariadb:105 security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the mariadb:105 module is now available for Red Hat Enterprise Linux 8Red Hat Produc ...
Synopsis Moderate: rh-mariadb105-mariadb security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-mariadb105-mariadb and rh-mariadb105-galera is now available for Red Hat Software Collec ...
Synopsis Moderate: mariadb:103 security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the mariadb:103 module is now available for Red Hat Enterprise Linux 84 Extended Update SupportRe ...
Synopsis Moderate: rh-mariadb103-mariadb security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collec ...
get_sort_by_table in MariaDB before 1062 allows an application crash via certain subquery uses of ORDER BY (CVE-2021-46657) MariaDB before 1072 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW (CVE-2021-46659) MariaDB through 1059 allows an application crash in find_field_in_tables ...
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB) Supported versions that are affected are 5734 and prior and 8025 and prior Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server Successful attacks of this vulnerability can result i ...