Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 30 |
CVE-ID | CVE-2020-14633 CVE-2020-14654 CVE-2020-14550 CVE-2020-14623 CVE-2020-14576 CVE-2020-14591 CVE-2020-14559 CVE-2020-14568 CVE-2020-14540 CVE-2020-14643 CVE-2020-14656 CVE-2020-14553 CVE-2020-14547 CVE-2020-14680 CVE-2020-14539 CVE-2020-14586 CVE-2020-14620 CVE-2020-14624 CVE-2020-14663 CVE-2020-14631 CVE-2020-14697 CVE-2020-14702 CVE-2020-14641 CVE-2020-14619 CVE-2020-14634 CVE-2020-14678 CVE-2020-14597 CVE-2020-14632 CVE-2020-14651 CVE-2020-14575 |
CWE-ID | CWE-20 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Ubuntu Operating systems & Components / Operating system mysql-server-8.0 (Ubuntu package) Operating systems & Components / Operating system package or component mysql-server-5.7 (Ubuntu package) Operating systems & Components / Operating system package or component |
Vendor | Canonical Ltd. |
Security Bulletin
This security bulletin contains information about 30 vulnerabilities.
EUVDB-ID: #VU30111
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-14633
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to manipulate data.
The vulnerability exists due to improper input validation within the InnoDB component in MySQL Server. A remote privileged user can exploit this vulnerability to manipulate data.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30102
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14654
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30091
Risk: Medium
CVSSv4.0: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14550
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the C API component in MySQL Client. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30093
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14623
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the InnoDB component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30088
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14576
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: UDF component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30084
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14591
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Audit Plug-in component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30109
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-14559
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Server: Information Schema component in MySQL Server. A remote authenticated user can exploit this vulnerability to gain access to sensitive information.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30092
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14568
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the InnoDB component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30094
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14540
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: DML component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30089
Risk: Medium
CVSSv4.0: 4.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14643
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to damange or delete data.
The vulnerability exists due to improper input validation within the Server: Security: Roles component in MySQL Server. A remote privileged user can exploit this vulnerability to damange or delete data.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30098
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14656
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Locking component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30110
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-14553
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to manipulate data.
The vulnerability exists due to improper input validation within the Server: Pluggable Auth component in MySQL Server. A remote authenticated user can exploit this vulnerability to manipulate data.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30099
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14547
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30086
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14680
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30085
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14539
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30106
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14586
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Security: Privileges component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30096
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14620
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: DML component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30097
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14624
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: JSON component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30081
Risk: Medium
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14663
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Server: Security: Privileges component in MySQL Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30105
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14631
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Security: Audit component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30083
Risk: Medium
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14697
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Server: Security: Privileges component in MySQL Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30107
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14702
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Security: Privileges component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30108
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14641
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Server: Security: Roles component in MySQL Server. A remote privileged user can exploit this vulnerability to gain access to sensitive information.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30087
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14619
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote authenticated user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Parser component in MySQL Server. A remote authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30112
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2020-14634
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to gain access to sensitive information.
The vulnerability exists due to improper input validation within the InnoDB component in MySQL Server. A remote privileged user can exploit this vulnerability to gain access to sensitive information.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30082
Risk: Medium
CVSSv4.0: 6.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14678
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Server: Security: Privileges component in MySQL Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30100
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14597
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Optimizer component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30103
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14632
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: Options component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30090
Risk: Medium
CVSSv4.0: 4.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14651
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to damange or delete data.
The vulnerability exists due to improper input validation within the Server: Security: Roles component in MySQL Server. A remote privileged user can exploit this vulnerability to damange or delete data.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU30095
Risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14575
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Server: DML component in MySQL Server. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationUpdate the affected package mysql-5.7 to the latest version.
Vulnerable software versionsUbuntu: 16.04 - 20.04
mysql-server-8.0 (Ubuntu package): before 8.0.21-0ubuntu0.20.04.3
mysql-server-5.7 (Ubuntu package): before 5.7.31-0ubuntu0.16.04.1
CPE2.3https://ubuntu.com/security/notices/USN-4441-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.