<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:14:55 +0000</lastBuildDate>
    <item>
      <title>certfr-2017-avi-122 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Oracle MySQL&lt;/span&gt;. Certaines d'entre elles pe…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2017-avi-122</link>
      <description>certfr-2017-avi-122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2017-avi-122</guid>
    </item>
    <item>
      <title>cnvd-2017-04744</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-04744</link>
      <description>cnvd-2017-04744</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-04744</guid>
    </item>
    <item>
      <title>EUVD-2026-193606</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-193606</link>
      <description>EUVD-2026-193606</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-193606</guid>
    </item>
    <item>
      <title>fkie_cve-2017-3305</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-3305</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-3305</guid>
    </item>
    <item>
      <title>GHSA-7568-gxg7-r8h9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7568-gxg7-r8h9</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7568-gxg7-r8h9</guid>
    </item>
    <item>
      <title>gsd-2017-3305</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-3305</link>
      <description>gsd-2017-3305</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-3305</guid>
    </item>
    <item>
      <title>RHSA-2017:2787 — Red Hat Security Advisory: rh-mysql56-mysql security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:2787</link>
      <description>&lt;p&gt;mysql: Incorrect input validation allowing code execution via mysqldump mysql: Server: Replication  unspecified vulnerability (CPU Jan 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2017) mysql: Server: DML unspecified vulnerability (CPU Jan 2017) mysql: Server: InnoDB unspecified vulnerability (CPU Jan 2017) mysql: Server: DDL unspecified vulnerability (CPU Jan 2017) mysql: unsafe chmod/chown use in init script (CPU Jan 2017) mysql: Server: DDL  unspecified vulnerability (CPU Jan 2017) mysql: unrestricted mysqld_safe&amp;#39;s ledir (CPU Jan 2017) mysql: prepared statement handle use-after-free after disconnect mysql: incorrect enforcement of ssl-mode=REQUIRED in MySQL 5.5 and 5.6 mysql: Server: DML unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 fix (CPU Jan 2017) mysql: Server: MyISAM unspecified vulnerability (CPU Jan 2017) mysql: Logging unspecified vulnerability (CPU Jan 2017) mysql: Server: Error Handling unspecified vulnerability (CPU Jan 2017) mysql: Server: Memcached unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: Server: DML unspecified vulnerability (CPU Apr 2017) mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2017) mysql: Server: Security: Privileges unspecifie…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql: Incorrect input validation allowing code execution via mysqldump mysql: Server: Replication  unspecified vulnerability (CPU Jan 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2017) mysql: Server: DML unspecified vulnerability (CPU Jan 2017) mysql: Server: InnoDB unspecified vulnerability (CPU Jan 2017) mysql: Server: DDL unspecified vulnerability (CPU Jan 2017) mysql: unsafe chmod/chown use in init script (CPU Jan 2017) mysql: Server: DDL  unspecified vulnerability (CPU Jan 2017) mysql: unrestricted mysqld_safe&amp;#39;s ledir (CPU Jan 2017) mysql: prepared statement handle use-after-free after disconnect mysql: incorrect enforcement of ssl-mode=REQUIRED in MySQL 5.5 and 5.6 mysql: Server: DML unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: insecure error log file handling in mysqld_safe, incomplete CVE-2016-6664 fix (CPU Jan 2017) mysql: Server: MyISAM unspecified vulnerability (CPU Jan 2017) mysql: Logging unspecified vulnerability (CPU Jan 2017) mysql: Server: Error Handling unspecified vulnerability (CPU Jan 2017) mysql: Server: Memcached unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2017) mysql: Server: DML unspecified vulnerability (CPU Apr 2017) mysql: Server: Security: Privileges unspecified vulnerability (CPU Apr 2017) mysql: Server: Security: Privileges unspecifie…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:2787</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:1137-1 — Security update for mysql</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:1137-1</link>
      <description>&lt;p&gt;Security update for mysql&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mysql&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:1137-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-3305</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3305</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlier and 5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue allows man-in-the-middle attackers to hijack the authentication of users by leveraging incorrect ordering of security parameter verification in a client, aka, &amp;#34;The Riddle&amp;#34;.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-3305</guid>
    </item>
  </channel>
</rss>
