peter bassill · operator
$ cve CVE-2009-4019 JSON

CVE-2009-4019 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 16.3% (pctl 97)

Patch early

A public exploit exists.

Description

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS16.26% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2009-11-30
Last modified2026-06-16

Affected (2)

VendorProduct
mysqlmysql
oraclemysql

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD