VendorsPingCAPtidball versions
Vulnerabilities

PingCAP TiDB

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-3023
Use of Externally-Controlled Format String in pingcap/tidb
Published 2022-11-04 · Modified
9.8EPSS 0.006
CVE-2024-41433
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reproduction of this issue did not cause the security impact of service interruption to other users. They argue that this is a complex query bug and not a DoS vulnerability.
Published 2024-09-03 · Analyzed
9.8EPSS 0.006
CVE-2022-31011
TiDB authentication bypass vulnerability
Published 2022-05-31 · Modified
7.8EPSS 0.003
CVE-2022-34969
PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
Published 2022-08-03 · Modified
7.5EPSS 0.009
CVE-2024-35618
PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
Published 2024-05-24 · Analyzed
7.5EPSS 0.004
CVE-2024-33809
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.
Published 2024-05-24 · Analyzed
6.5EPSS 0.004
CVE-2024-41434
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows attackers to cause a Denial of Service (DoS) via a crafted input to the 'RemoveUnnecessaryFirstRow', it will check the expression between 'Agg' and 'GroupBy', but does not check the return type. NOTE: PingCAP disputes this, arguing that reproduction did not cause the security impact of service interruption to other users. They maintain it is a complex query bug in the product but not a DoS.
Published 2024-09-03 · Analyzed
4.3EPSS 0.004