VDB

GCVE-110-NCSC-2025-339

GCVE-110-NCSC-2025-339
Advisory PublishedCVSS 5.3/10
Vulnetix · Advisory published October 23, 2025
Multiple vulnerabilities in Oracle MySQL Server and Cluster, along with libcurl's WebSocket code, allow for various denial of service attacks, with CVSS scores ranging from 4.3 to 7.5.

Weaknesses (CWE)

CWE-407Inefficient Algorithmic ComplexityCWE-670Always-Incorrect Control Flow ImplementationCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-197Numeric Truncation ErrorCWE-400Uncontrolled Resource ConsumptionCWE-770Allocation of Resources Without Limits or Throttling

Risk Scores

CVSS 3.1
5.3/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersionsPlatforms
Oraclevers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,557 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›