<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:48:06 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:1671 — Important: mysql security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:1671</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: mysql, AlmaLinux:9: mysql-common, AlmaLinux:9: mysql-devel, AlmaLinux:9: mysql-errmsg, AlmaLinux:9: mysql-libs, AlmaLinux:9: mysql-server, AlmaLinux:9: mysql-test&lt;/p&gt;
&lt;p&gt;MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: SSL_select_next_proto buffer overread (CVE-2024-5535)
  * krb5: GSS message token handling (CVE-2024-37371)
  * curl: libcurl: ASN.1 date parser overread (CVE-2024-7264)
  * mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) (CVE-2024-21238)
  * mysql: X Plugin unspecified vulnerability (CPU Oct 2024) (CVE-2024-21196)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21241)
  * mysql: Client programs unspecified vulnerability (CPU Oct 2024) (CVE-2024-21231)
  * mysql: Information Schema unspecified vulnerability (CPU Oct 2024) (CVE-2024-21197)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21218)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21201)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21236)
  * mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21237)
  * mysql: FTS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21203)
  * mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) (CVE-2024-21212)
  * mysql: DML unspecified vulnerability (CPU Oct 2024) (CVE-2024-21219)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21230)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21213)
  * mysql: InnoDB unspec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: mysql, AlmaLinux:9: mysql-common, AlmaLinux:9: mysql-devel, AlmaLinux:9: mysql-errmsg, AlmaLinux:9: mysql-libs, AlmaLinux:9: mysql-server, AlmaLinux:9: mysql-test&lt;/p&gt;
&lt;p&gt;MySQL is a multi-user, multi-threaded SQL database server. It consists of the MySQL server daemon (mysqld) and many client programs and libraries.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: SSL_select_next_proto buffer overread (CVE-2024-5535)
  * krb5: GSS message token handling (CVE-2024-37371)
  * curl: libcurl: ASN.1 date parser overread (CVE-2024-7264)
  * mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) (CVE-2024-21238)
  * mysql: X Plugin unspecified vulnerability (CPU Oct 2024) (CVE-2024-21196)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21241)
  * mysql: Client programs unspecified vulnerability (CPU Oct 2024) (CVE-2024-21231)
  * mysql: Information Schema unspecified vulnerability (CPU Oct 2024) (CVE-2024-21197)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21218)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21201)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21236)
  * mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21237)
  * mysql: FTS unspecified vulnerability (CPU Oct 2024) (CVE-2024-21203)
  * mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) (CVE-2024-21212)
  * mysql: DML unspecified vulnerability (CPU Oct 2024) (CVE-2024-21219)
  * mysql: Optimizer unspecified vulnerability (CPU Oct 2024) (CVE-2024-21230)
  * mysql: InnoDB unspecified vulnerability (CPU Oct 2024) (CVE-2024-21213)
  * mysql: InnoDB unspec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:1671</guid>
    </item>
    <item>
      <title>bdu:2024-08448</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-08448</link>
      <description>bdu:2024-08448</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-08448</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0884 — De multiples vulnérabilités ont été découvertes dans Oracle MySQL. Elles permettent à un attaquant de provoquer un déni…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0884</link>
      <description>certfr-2024-avi-0884</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0884</guid>
    </item>
    <item>
      <title>cnvd-2024-42454</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-42454</link>
      <description>cnvd-2024-42454</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-42454</guid>
    </item>
    <item>
      <title>EUVD-2026-258539</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258539</link>
      <description>EUVD-2026-258539</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258539</guid>
    </item>
    <item>
      <title>fkie_cve-2024-21219</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-21219</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-21219</guid>
    </item>
    <item>
      <title>GHSA-c72q-9j4p-2mp4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c72q-9j4p-2mp4</link>
      <description>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c72q-9j4p-2mp4</guid>
    </item>
    <item>
      <title>gsd-2024-21219</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-21219</link>
      <description>gsd-2024-21219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-21219</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-21219 — Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affect…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-21219</link>
      <description>msrc_CVE-2024-21219</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-21219</guid>
    </item>
    <item>
      <title>OESA-2024-2287 — mysql security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: mysql, openEuler:22.03-LTS-SP4: mysql, openEuler:22.03-LTS-SP3: mysql, openEuler:20.03-LTS-SP4: mysql, openEuler:22.03-LTS-SP1: mysql&lt;/p&gt;
&lt;p&gt;The MySQL(TM) software delivers a very fast, multi-threaded, multi-user, and robust SQL (Structured Query Language) database server. MySQL Server is intended for mission-critical, heavy-load production systems as well as for embedding into mass-deployed software. MySQL is a trademark of Oracle and/or its affiliates&#13;
&#13;
Security Fix(es):&#13;
&#13;
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.38, 8.4.1 and  9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2024-21185)&#13;
&#13;
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: mysql, openEuler:22.03-LTS-SP4: mysql, openEuler:22.03-LTS-SP3: mysql, openEuler:20.03-LTS-SP4: mysql, openEuler:22.03-LTS-SP1: mysql&lt;/p&gt;
&lt;p&gt;The MySQL(TM) software delivers a very fast, multi-threaded, multi-user, and robust SQL (Structured Query Language) database server. MySQL Server is intended for mission-critical, heavy-load production systems as well as for embedding into mass-deployed software. MySQL is a trademark of Oracle and/or its affiliates&#13;
&#13;
Security Fix(es):&#13;
&#13;
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.38, 8.4.1 and  9.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-2024-21185)&#13;
&#13;
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).(CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2287</guid>
    </item>
    <item>
      <title>RHSA-2025:1671 — Red Hat Security Advisory: mysql security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1671</link>
      <description>&lt;p&gt;openssl: SSL_select_next_proto buffer overread curl: libcurl: ASN.1 date parser overread curl: curl netrc password leak mysql: PS unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: X Plugin unspecified vulnerability (CPU Oct 2024) mysql: Information Schema unspecified vulnerability (CPU Oct 2024) mysql: DDL unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: FTS unspecified vulnerability (CPU Oct 2024) mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: DML unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: Client programs unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: mysqldump unspecified vulnerability (CPU Oct 2024) krb5: GSS message token handling mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) mysql: MySQL Server InnoDB Denial of Service and Unauthorized Data Modification Vulnerability mysql…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: SSL_select_next_proto buffer overread curl: libcurl: ASN.1 date parser overread curl: curl netrc password leak mysql: PS unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: X Plugin unspecified vulnerability (CPU Oct 2024) mysql: Information Schema unspecified vulnerability (CPU Oct 2024) mysql: DDL unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: FTS unspecified vulnerability (CPU Oct 2024) mysql: Health Monitor unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: DML unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: Client programs unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Group Replication GCS unspecified vulnerability (CPU Oct 2024) mysql: Thread Pooling unspecified vulnerability (CPU Oct 2024) mysql: InnoDB unspecified vulnerability (CPU Oct 2024) mysql: Optimizer unspecified vulnerability (CPU Oct 2024) mysql: mysqldump unspecified vulnerability (CPU Oct 2024) krb5: GSS message token handling mysql: mariadb: High Privilege Denial of Service Vulnerability in MySQL Server (CPU Jan 2025) mysql: MySQL Server InnoDB Denial of Service and Unauthorized Data Modification Vulnerability mysql…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1671</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-21219</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21219</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:Pro:16.04:LTS: mysql-5.7, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6, Ubuntu:Pro:18.04:LTS: mysql-5.7, Ubuntu:20.04:LTS: mysql-8.0, Ubuntu:22.04:LTS: mysql-8.0, Ubuntu:24.04:LTS: mysql-8.0&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: mysql-5.5, Ubuntu:Pro:16.04:LTS: mysql-5.7, Ubuntu:16.04:LTS: percona-server-5.6, Ubuntu:16.04:LTS: percona-xtradb-cluster-5.6, Ubuntu:Pro:18.04:LTS: mysql-5.7, Ubuntu:20.04:LTS: mysql-8.0, Ubuntu:22.04:LTS: mysql-8.0, Ubuntu:24.04:LTS: mysql-8.0&lt;/p&gt;
&lt;p&gt;Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-21219</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3188 — Oracle MySQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3188</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3188</guid>
    </item>
  </channel>
</rss>
