Back

CVE-2004-0957

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.

Published: Feb 9, 2005 Modified: Jun 16, 2026
NVD-CWE-noinfo

CVSS Metrics

Affected Products (99)

Vendor Product Version
openpkg openpkg 2.1
openpkg openpkg 2.2
openpkg openpkg current
oracle mysql 3.20
oracle mysql 3.20.32a
oracle mysql 3.21
oracle mysql 3.22
oracle mysql 3.22.26
oracle mysql 3.22.27
oracle mysql 3.22.28
oracle mysql 3.22.29
oracle mysql 3.22.30
oracle mysql 3.22.32
oracle mysql 3.23
oracle mysql 3.23.2
oracle mysql 3.23.3
oracle mysql 3.23.4
oracle mysql 3.23.5
oracle mysql 3.23.8
oracle mysql 3.23.9

…and 79 more

GitHub Security Advisory GHSA-hx63-8p37-c3fh

Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a...

Risk Scores

CVSS Score 6.8 / 10
EPSS Score 2.43%

Top 17% most likely to be exploited

Threat Score 27.9 / 100

Data Sources

NVD EPSS GitHub