← Vulnerability feed

Vulnerability record · CVE-2004-0628 · published 6 December 2004

CVE-2004-0628: Mysql vulnerability

Mysql · Mysql

Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.

10.0 CVSS 2.0 High EPSS 7.8% · top 5.5%
10.0CVSS 2.0 base score
7.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0628 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0627MySQL authentication bypass via zero-length scrambled stringThe check_scramble_323 function in MySQL 4.1.x before 4.1.3 and 5.0 fails to properly validate a zero-length scrambled authentication string, allowin…EPSS 70%analysed9.0CVE-2003-0780MySQL get_salt_from_password buffer overflow allows code executionMySQL 4.0.14 and earlier, plus 3.23.x, contain a buffer overflow in get_salt_from_password in sql_acl.cc. An attacker with ALTER TABLE privileges can…EPSS 78%analysed8.5CVE-2009-2446Mysql vulnerabilityMultiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remot…EPSS 11%7.8CVE-2017-15945Mariadb incorrect permission assignment vulnerabilityThe installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages …EPSS 0.37%7.5CVE-2012-0553Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulner…EPSS 2.6%7.5CVE-2013-1492Mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulner…EPSS 2.8%7.5CVE-2012-0882Oracle mysql memory buffer overflow vulnerabilityBuffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at…EPSS 5.3%7.5CVE-2008-0226yaSSL buffer overflows in handshake and input parsingyaSSL 1.7.5 and earlier contains multiple buffer overflows in the ProcessOldClientHello function (handshake.cpp) and the "input_buffer& operator>>" r…EPSS 92%analysed

Source: NIST National Vulnerability Database (record CVE-2004-0628), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.