<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:26:18 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:0737 — Moderate: mariadb:10.11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:0737</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: Judy, AlmaLinux:8: galera, AlmaLinux:8: mariadb, AlmaLinux:8: mariadb-backup, AlmaLinux:8: mariadb-common, AlmaLinux:8: mariadb-devel, AlmaLinux:8: mariadb-embedded, AlmaLinux:8: mariadb-embedded-devel, AlmaLinux:8: mariadb-errmsg, AlmaLinux:8: mariadb-gssapi-server and 6 more&lt;/p&gt;
&lt;p&gt;MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) (CVE-2024-21096)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: Judy, AlmaLinux:8: galera, AlmaLinux:8: mariadb, AlmaLinux:8: mariadb-backup, AlmaLinux:8: mariadb-common, AlmaLinux:8: mariadb-devel, AlmaLinux:8: mariadb-embedded, AlmaLinux:8: mariadb-embedded-devel, AlmaLinux:8: mariadb-errmsg, AlmaLinux:8: mariadb-gssapi-server and 6 more&lt;/p&gt;
&lt;p&gt;MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) (CVE-2024-21096)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:0737</guid>
    </item>
    <item>
      <title>bdu:2024-04356</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04356</link>
      <description>bdu:2024-04356</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04356</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-21096</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-21096</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: mariadb, Alpaquita:stream: mariadb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: mariadb, Alpaquita:stream: mariadb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-21096</guid>
    </item>
    <item>
      <title>BIT-mariadb-2024-21096</title>
      <link>https://cve.radiocsirt.org/vuln/bit-mariadb-2024-21096</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: mariadb&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-mariadb-2024-21096</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0326 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles
permettent à un attaquant de provoquer un déni…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0326</link>
      <description>certfr-2024-avi-0326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0326</guid>
    </item>
    <item>
      <title>cnvd-2024-34925</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-34925</link>
      <description>cnvd-2024-34925</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-34925</guid>
    </item>
    <item>
      <title>EUVD-2026-217173</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217173</link>
      <description>EUVD-2026-217173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217173</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21096</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21096</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21096</guid>
    </item>
    <item>
      <title>GHSA-3vx9-2ch5-m6r6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vx9-2ch5-m6r6</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vx9-2ch5-m6r6</guid>
    </item>
    <item>
      <title>gsd-2024-21096</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21096</link>
      <description>gsd-2024-21096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21096</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-21096 — Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-21096</link>
      <description>msrc_CVE-2024-21096</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-21096</guid>
    </item>
    <item>
      <title>OESA-2024-1558 — mysql security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1558</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: mysql&lt;/p&gt;
&lt;p&gt;The MySQL(TM) software delivers a very fast, multi-threaded, multi-user, and robust SQL (Structured Query Language) database server. MySQL Server is intended for mission-critical, heavy-load production systems as well as for embedding into mass-deployed software. MySQL is a trademark of Oracle and/or its affiliates&#13;
&#13;
Security Fix(es):&#13;
&#13;
Issue summary: The POLY1305 MAC (message authentication code) implementation
contains a bug that might corrupt the internal state of applications running
on PowerPC CPU based platforms if the CPU provides vector instructions.&#13;
&#13;
Impact summary: If an attacker can influence whether the POLY1305 MAC
algorithm is used, the application state might be corrupted with various
application dependent consequences.&#13;
&#13;
The POLY1305 MAC (message authentication code) implementation in OpenSSL for
PowerPC CPUs restores the contents of vector registers in a different order
than they are saved. Thus the contents of some of these vector registers
are corrupted when returning to the caller. The vulnerable code is used only
on newer PowerPC processors supporting the PowerISA 2.07 instructions.&#13;
&#13;
The consequences of this kind of internal application state corruption can
be various - from no consequences, if the calling application does not
depend on the contents of non-volatile XMM registers at all, to the worst
consequences, where the attacker could get complete control of the application
process. However unless the compiler uses the vector registers for stor…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP2: mysql&lt;/p&gt;
&lt;p&gt;The MySQL(TM) software delivers a very fast, multi-threaded, multi-user, and robust SQL (Structured Query Language) database server. MySQL Server is intended for mission-critical, heavy-load production systems as well as for embedding into mass-deployed software. MySQL is a trademark of Oracle and/or its affiliates&#13;
&#13;
Security Fix(es):&#13;
&#13;
Issue summary: The POLY1305 MAC (message authentication code) implementation
contains a bug that might corrupt the internal state of applications running
on PowerPC CPU based platforms if the CPU provides vector instructions.&#13;
&#13;
Impact summary: If an attacker can influence whether the POLY1305 MAC
algorithm is used, the application state might be corrupted with various
application dependent consequences.&#13;
&#13;
The POLY1305 MAC (message authentication code) implementation in OpenSSL for
PowerPC CPUs restores the contents of vector registers in a different order
than they are saved. Thus the contents of some of these vector registers
are corrupted when returning to the caller. The vulnerable code is used only
on newer PowerPC processors supporting the PowerISA 2.07 instructions.&#13;
&#13;
The consequences of this kind of internal application state corruption can
be various - from no consequences, if the calling application does not
depend on the contents of non-volatile XMM registers at all, to the worst
consequences, where the attacker could get complete control of the application
process. However unless the compiler uses the vector registers for stor…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1558</guid>
    </item>
    <item>
      <title>RHSA-2025:0737 — Red Hat Security Advisory: mariadb:10.11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:0737</link>
      <description>&lt;p&gt;mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:0737</guid>
    </item>
    <item>
      <title>RHSA-2026:0335 — Red Hat Security Advisory: mariadb:10.11 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0335</link>
      <description>&lt;p&gt;mariadb: MariaDB Server Crash Due to Empty Backtrace Log mariadb: MariaDB Server Crash via Item_direct_view_ref mariadb: MariaDB Server Crash mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) mariadb: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) mysql: mariadb: InnoDB unspecified vulnerability (CPU Apr 2025) mysql: mariadb: mysqldump unspecified vulnerability (CPU Apr 2025) mysql: Optimizer unspecified vulnerability (CPU Jan 2026)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;mariadb: MariaDB Server Crash Due to Empty Backtrace Log mariadb: MariaDB Server Crash via Item_direct_view_ref mariadb: MariaDB Server Crash mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) mariadb: MariaDB: mariadb-dump utility vulnerable to remote code execution via improper path validation mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) mysql: mariadb: InnoDB unspecified vulnerability (CPU Apr 2025) mysql: mariadb: mysqldump unspecified vulnerability (CPU Apr 2025) mysql: Optimizer unspecified vulnerability (CPU Jan 2026)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0335</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2032-1 — Security update for mariadb</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2032-1</link>
      <description>&lt;p&gt;Security update for mariadb&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for mariadb&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2032-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-21096</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21096</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:Pro:16.04:LTS: mysql-5.7, Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6, Ubuntu:Pro:18.04:LTS: mysql-5.7, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mysql-8.0, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6 and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:Pro:16.04:LTS: mysql-5.7, Ubuntu:16.04:LTS: mariadb-10.0, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6, Ubuntu:Pro:18.04:LTS: mysql-5.7, Ubuntu:18.04:LTS: mariadb-10.1, Ubuntu:20.04:LTS: mysql-8.0, Ubuntu:20.04:LTS: mariadb-10.3, Ubuntu:22.04:LTS: mariadb-10.6 and 3 more&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.36 and prior and  8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21096</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0894 — Oracle MySQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0894</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0894</guid>
    </item>
  </channel>
</rss>
