MariaDB 服务器是 MySQL 服务器的一个由社区开发的分支。在版本 10.6.1 至 10.6.28、10.11.19、11.4.13、11.8.9、12.3.3 和 13.0.2 中,CONNECT 引擎的 DOS 表类型存在一个不正确的边界检查漏洞,允许在攻击者可控的偏移量处向栈缓冲区之外写入一个空字节(即发生栈溢出)。拥有 CONNECT 引擎权限的已认证用户可利用此漏洞导致数据库服务崩溃,并可能实现远程代码执行。该问题已在版本 10.6.28、10.11.19、11.4.13、11.8.9、12.3
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107819 | 5.9 MEDIUM | MariaDB Connector/C: libmariadb allowed cleartext password leakage on TLS hostname verific |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet