MariaDB Connector/C 是一个用于将应用程序连接到 MariaDB 和 MySQL 数据库的 C/C++ 客户端库。在版本 3.4.1 至 3.4.10 之间,MariaDB Connector/C 的 libmariadb 组件中零配置 SSL 认证切换逻辑存在缺陷:虽然会检查证书信任失败的情况,但在选择非哈希认证插件之前,未对 TLS 主机名验证不匹配的情况进行拒绝。因此,拥有其他主机名有效证书的活动中间人(MITM)攻击者可以请求使用 mysql_clear_password 认证方式,并在攻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107815 | 8.5 HIGH | MariaDB: one byte OOB write in DOS tables of the CONNECT engine |
| CVE-2026-107814 | 8.4 HIGH | MariaDB: Insecure $HOME in MariaDB rpm packages |
| CVE-2026-107818 | 8.4 HIGH | MariaDB: environment injection via wsrep bootstrap in the mariadb.service file |
| CVE-2026-107821 | 8.0 HIGH | MariaDB: insufficient validation of binary frm data when opening a table |
| CVE-2026-107823 | 7.2 HIGH | MariaDB: privilege escalation via incorrect view frm parsing |
| CVE-2026-107816 | 6.4 MEDIUM | MariaDB: `qc_info` plugin can do OOB reads if query contains \0 |
| CVE-2026-107822 | 6.4 MEDIUM | MariaDB: database privilege escalation via user / role name collision in the acl cache |
| CVE-2026-107817 | 4.4 MEDIUM | MariaDB: mysql_json plugin OOB reads |
No comments yet