← Vulnerability feed

Vulnerability record · CVE-2005-0684 · published 25 April 2005

CVE-2005-0684: MySQL MaxDB web tool buffer overflows allow remote code execution

Mysql · Maxdb

The MySQL MaxDB web tool before 7.5.00.26 contains multiple buffer overflows, one reachable through an HTTP GET request with a long file parameter after a percent sign and another through a long Lock-Token string in the WebDAV functionality. The WebDAV overflow is caused by improper handling in the getLockTokenHeader function in WDVHandler_CommonUtils.c. Successful exploitation lets a remote, unauthenticated attacker execute arbitrary code on the affected service.

10.0 CVSS 2.0 High EPSS 69% · top 0.7%
10.0CVSS 2.0 base score
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score is 10 with complete confidentiality, integrity and availability impact from an unauthenticated network vector, and EPSS is very high.

What it is

The MySQL MaxDB web tool before 7.5.00.26 contains multiple buffer overflows, one reachable through an HTTP GET request with a long file parameter after a percent sign and another through a long Lock-Token string in the WebDAV functionality. The WebDAV overflow is caused by improper handling in the getLockTokenHeader function in WDVHandler_CommonUtils.c. Successful exploitation lets a remote, unauthenticated attacker execute arbitrary code on the affected service.

Impact

An attacker gains remote code execution with the privileges of the MaxDB web tool process, which can lead to full compromise of the host and any data it manages.

Attack surface

The flaws are reached over the network through the MaxDB web tool's HTTP and WebDAV interfaces, requiring no authentication and no user interaction per the AV:N/AC:L/Au:N vector.

Exploitation

No CISA KEV listing and no public exploit references are present, but EPSS is 0.68504 (99.3rd percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade MySQL MaxDB to 7.5.00.26 or later, which the vendor advisory and patch references address.
  • If the web tool and WebDAV functionality are not required, disable or block them.
  • Restrict network access to the MaxDB web tool to trusted management hosts only.
  • Monitor vendor advisories for any further updates to the affected component.

Detection

  • Inspect HTTP GET requests to the MaxDB web tool for unusually long file parameters, especially those containing a percent sign.
  • Inspect WebDAV requests for abnormally long Lock-Token header values.
  • Alert on crashes or restarts of the MaxDB web tool process that coincide with HTTP or WebDAV traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0684 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-4305SAP DB and MaxDB buffer overflow via long database name in WebDBM clientSAP DB and MaxDB before 7.6.00.30 contain a buffer overflow that is triggered when a remote attacker supplies an overly long database name while conn…EPSS 71%analysed10.0CVE-2005-1274Mysql maxdb vulnerabilityStack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execut…EPSS 4.2%10.0CVE-2004-1168Mysql maxdb vulnerabilityStack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a lon…EPSS 4.6%7.5CVE-2005-0111Mysql maxdb vulnerabilityStack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password par…EPSS 3.8%5.0CVE-2005-0083Mysql maxdb vulnerabilityMySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application …EPSS 1.4%5.0CVE-2005-0081Mysql maxdb vulnerabilityMySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invali…EPSS 1.5%5.0CVE-2005-0082Mysql maxdb vulnerabilityThe sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (cr…EPSS 1.4%5.0CVE-2004-1169Mysql maxdb vulnerabilityMaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2005-0684), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.