peter bassill · operator
$ cve CVE-2010-3678 JSON

CVE-2010-3678 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 12.2% (pctl 96)

Patch early

A public exploit exists.

Description

Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (crash) via (1) IN or (2) CASE operations with NULL arguments that are explicitly specified or indirectly provided by the WITH ROLLUP modifier.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS12.23% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2011-01-11
Last modified2026-06-16

Affected (2)

VendorProduct
mysqlmysql
oraclemysql

Public exploits

SourceTitleDate
exploit-dbOracle MySQL < 5.1.49 - 'WITH ROLLUP' Denial of Service2010-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD