peter bassill · operator
$ cve CVE-2012-5614 JSON

CVE-2012-5614 EXPLOIT

4.0
MEDIUM · CVSS 2.0 · EPSS 13.2% (pctl 96)

Patch early

A public exploit exists.

Description

Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote authenticated users to cause a denial of service (mysqld crash) via a SELECT command with an UpdateXML command containing XML with a large number of unique, nested elements.

Scoring

CVSS4.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
EPSS13.18% — more likely to be exploited than 96% of all CVEs
On CISA KEVno
Public exploityes
Published2012-12-03
Last modified2026-06-16

Affected (7)

VendorProduct
mariadbmariadb
oraclemysql
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux workstation

Public exploits

SourceTitleDate
exploit-dbMySQL - Denial of Service (PoC)2012-12-02

References

→ the Explorer  ·  watch your stack  ·  NVD