← Vulnerability feed

Vulnerability record · CVE-2005-0111 · published 13 January 2005

CVE-2005-0111: Mysql maxdb vulnerability

Mysql · Maxdb

Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

7.5 CVSS 2.0 High EPSS 3.8% · top 10.2%
7.5CVSS 2.0 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-4305SAP DB and MaxDB buffer overflow via long database name in WebDBM clientSAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while conn…EPSS 71%analysed10.0CVE-2005-1274Mysql maxdb vulnerabilityStack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execut…EPSS 4.2%10.0CVE-2005-0684MySQL MaxDB web tool buffer overflows allow remote code executionThe MySQL MaxDB web tool before 7.5.00.26 contains multiple buffer overflows, one reachable through an HTTP GET request with a long file parameter af…EPSS 69%analysed10.0CVE-2004-1168Mysql maxdb vulnerabilityStack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a lon…EPSS 4.6%5.0CVE-2005-0083Mysql maxdb vulnerabilityMySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application …EPSS 1.4%5.0CVE-2005-0081Mysql maxdb vulnerabilityMySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invali…EPSS 1.5%5.0CVE-2005-0082Mysql maxdb vulnerabilityThe sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (cr…EPSS 1.4%5.0CVE-2004-1169Mysql maxdb vulnerabilityMaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2005-0111), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.