peter bassill · operator
$ cve CVE-2008-0226 JSON

CVE-2008-0226 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 91.6% (pctl 100)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS91.6% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-01-10
Last modified2026-06-16

Affected (6)

VendorProduct
applemac os x
canonicalubuntu linux
debiandebian linux
mysqlmysql
oraclemysql
yasslyassl

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD