peter bassill · operator
$ cve CVE-2009-0819 JSON

CVE-2009-0819 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 10.2% (pctl 96)

Patch early

A public exploit exists.

Description

sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS10.18% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2009-03-05
Last modified2026-06-16

Affected (2)

VendorProduct
mysqlmysql
oraclemysql

Public exploits

SourceTitleDate
exploit-dbMySQL 6.0.9 - XPath Expression Remote Denial of Service2009-02-14

References

→ the Explorer  ·  watch your stack  ·  NVD