CVE-2007-1420

Advisory lineage Upstream: 0 Downstream: 1
Downstream
Modified
Published: 12 Mar 2007, 23:00
Last modified:07 Aug 2024, 12:59

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
2.1 LOW
v2.0 (nvd)
EPSS Score
0.06% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

12 Mar 2007, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 12:59
Last Modified
Vulnerability information updated

Description

MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and triggers a NULL dereference in the filesort function.

CVSS Metrics

  • v2.0LOWScore: 2.1AV:L/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 0.06% Percentile: 19%

Affected Systems

  • mysqlmysql

    ≤ 5.0.33 | 5.0.0 | 5.0.1 | 5.0.2 | 5.0.3 | 5.0.4 | 5.0.5 | 5.0.10 | 5.0.15 | 5.0.16 | 5.0.17 | 5.0.20 | 5.0.24 | 5.0.30

  • oraclemysql

    5.0.6 | 5.0.7 | 5.0.32 | 5.0.41

References (20)