VulnSea

mysql_connectors vulnerabilities

CVEs whose affected-version data names the mysql_connectors package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2021-44533Medium· 5.3
4y ago

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly

Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be inter…

▾ Sunlitnodejs · node.jsEPSS 9.4%via NVD
CVE-2021-3711Critical· 9.8
5y ago

In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt()

In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit…

▾ Midnightopenssl · opensslEPSS 88%via NVD
CVE-2021-3449Medium· 5.9PoC
5y ago

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHel…

▾ Twilightopenssl · opensslEPSS 64%via NVD
CVE-2021-3450High· 7.4PoC
5y ago

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain

The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that hav…

▾ Midnightopenssl · opensslEPSS 18%via NVD
CVE-2020-1967High· 7.5PoC
6y ago

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension

Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. Th…

▾ Midnightopenssl · opensslEPSS 53%via NVD
mysql_connectors vulnerabilities (CVEs) · VulnSea