← Vulnerability feed

Vulnerability record · CVE-2017-10788 · published 1 July 2017

CVE-2017-10788: Dbd-mysql project dbd-mysql use after free vulnerability

DDbd Mysql Project · Dbd Mysql

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

9.8 CVSS 3.0 Critical EPSS 4.6% · top 8.5% CWE-416 · Use after free
9.8CVSS 3.0 base score, v2 7.5
4.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-10788 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-8949Dbd-mysql project dbd-mysql use after free vulnerabilityUse-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call …EPSS 4.5%9.8CVE-2014-9906Debian linux use after free vulnerabilityUse-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary c…EPSS 6.1%8.1CVE-2016-1251Dbd-mysql project dbd-mysql use after free vulnerabilityThere is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.…EPSS 3.1%7.5CVE-2016-1246Dbd-mysql project dbd-mysql memory buffer overflow vulnerabilityBuffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors re…EPSS 4.1%5.9CVE-2017-10789Dbd-mysql project dbd-mysql vulnerabilityThe DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has …EPSS 2.2%5.9CVE-2016-1249Dbd-mysql project dbd-mysql out-of-bounds read vulnerabilityThe DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of…EPSS 2.4%7.0CVE-2026-68820Windows Ancillary Function Driver for WinSock use-after-free privilege escalationThe Windows Ancillary Function Driver for WinSock (afd.sys) contains a use-after-free (CWE-416) that lets an authorized local attacker elevate privil…KEVEPSS 0.33%analysed8.8CVE-2010-0806Microsoft Internet Explorer Peer Objects use-after-free allows remote code executionInternet Explorer 6, 6 SP1 and 7 contain a use-after-free in the Peer Objects component (iepeers.dll), where an object is accessed after deletion, le…KEVEPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2017-10788), CISA KEV, FIRST EPSS (scores of 2026-10-07). This page is refreshed as NVD updates the record.