VDB
CVE-2004-0835
CVE-2004-0835
PUBLISHED
CVSS 7.5 HIGH
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights of the original table instead of the target table in an ALTER TABLE RENAME operation, which could allow attackers to conduct unauthorized activities.
EPSS 22.35% · 97.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
22.35%
97.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| oracle | mysql | 3.20, 4.0.0 |
| n/a | n/a | n/a |
| mysql | mysql | 4.1.0, 5.0.0 |
| debian | debian_linux | 3.0 |
Timeline
- Oct 16, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- http://www.mysql.org/doc/refman/4.1/en/news-4-1-2.html url
- RHSA-2004:611 vendor-advisory
- 12783 third-party-advisory
- http://www.mysql.org/doc/refman/4.1/en/news-4-0-19.html url
- 2004-0054 vendor-advisory
- http://lists.mysql.com/internals/13073 url
- 1011606 vdb
- RHSA-2004:597 vendor-advisory
- P-018 third-party-advisory
- GLSA-200410-22 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0835 advisory
- http://bugs.mysql.com/bug.php?id=3270 url
- http://secunia.com/advisories/12783 url
- http://www.debian.org/security/2004/dsa-562 url
- http://www.trustix.org/errata/2004/0054 url
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17666 advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000892 technical
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101864-1 technical
- http://www.securityfocus.com/bid/11357 exploit