Security Vulnerabilities (CVE) Fixed in MariaDB
Lists of Security Vulnerabilities (CVE) fixed in MariaDB products.
Sensitive security issues can be reported on https://hackerone.com/mariadb or sent directly to the persons responsible for MariaDB security: security [AT] mariadb (dot) org.
What is a CVE?
Common Vulnerabilities and Exposures (CVE) relate to flaws "in a software, firmware, hardware, or service component resulting from a weakness that can be exploited, causing a negative impact to the confidentiality, integrity, or availability of an impacted component or components."
It is a publicly available and free-to-use database of known software vulnerabilities maintained at https://cve.mitre.org/.
For additional information, see CVE Glossary at cve.org
What is a CVSS Score?
Common Vulnerability Scoring System (CVSS) is "an open framework for communicating the characteristics and severity of software vulnerabilities."
For additional information, see Vulnerability Metrics at nvd.nist.gov
Fixed Security Vulnerabilities
This page contains a full list of CVEs fixed in all versions and series of MariaDB Enterprise Server.
This page contains a full list of CVEs fixed in all versions and series of MariaDB Community Server.
Some CVE apply to MySQL but are not present in MariaDB Enterprise Server or MariaDB Community Server; these are listed on the Security Vulnerabilities fixed in Oracle MySQL that did not exist in MariaDB page.
This page is licensed: CC BY-SA / Gnu FDL
Last updated
Was this helpful?

