Orange Business Services
Vigil@nce Vigil@nce Vigil@nce
we track for your security since 1999
  home presentation vulnerabilities documentation contact  
subscriber area subscriber area
free access free access
The Vigil@nce team watches vulnerabilities impacting your computers, and then offers solutions, a database and tools to correct them.
recent vulnerabilities recent vulnerabilities
tracked products tracked products
RSS feed RSS feed
vulnerable product
Vulnerabilities of MySQL Enterprise

MySQL Enterprise vulnerability: several vulnerabilities of April 2013
Several vulnerabilities of MySQL are fixed by the CPU of April 2013.

MySQL Enterprise vulnerability: information disclosure in CBC mode, Lucky 13
An attacker can inject wrongly encrypted messages in a TLS/DTLS session in mode CBC, and measure the delay before the error message reception, in order to progressively guess the clear content of the session.

MySQL Enterprise vulnerability: five vulnerabilities
Several vulnerabilities of MySQL can be used by a remote attacker to create a denial of service, raise its privileges, or execute some code.

MySQL Enterprise vulnerability: access bypass via symlink
A local attacker can use a symbolic link, in order to bypass access restrictions of a MySQL table.

MySQL Enterprise vulnerability: SQL injection via quote
An attacker, who is authenticated on MySQL and who is allowed to alter tables, can use a special character, which is saved in the Binary Log, and which is then used to execute SQL code during the replication.

Display other vulnerabilities of MySQL Enterprise described by Vigil@nce...

Display information about MySQL Enterprise:



















Copyright 1999-2013 Vigil@nce. Vigil@nce is a service from Orange Business Services. Site map. Legal notice. Version française