← All CVEs

CVE-2012-5614

medium · 4

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

4
CVSS
13.2%
EPSS (exploit prob.)
96th
EPSS percentile
2012-12-03
Published

AV:N/AC:L/Au:S/C:N/I:N/A:P

Affected products

VendorProductAffected versions
oraclemysql>= 5.1.0, <= 5.1.67
oraclemysql>= 5.5.0, <= 5.5.29
mariadbmariadb>= 5.5.0, < 5.5.30
mariadbmariadb>= 10.0.0, < 10.0.2
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_eus6.4
redhatenterprise_linux_server6.0
redhatenterprise_linux_server_aus6.4
redhatenterprise_linux_workstation6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2012-5614