Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 16 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mariadb mariadb
|
|
| CPEs | cpe:2.3:a:mariadb:mariadb:3.3.18:*:*:*:*:*:*:* cpe:2.3:a:mariadb:mariadb:3.4.8:*:*:*:*:*:*:* |
|
| Vendors & Products |
Mariadb mariadb
|
|
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mariadb
Mariadb server |
|
| Vendors & Products |
Mariadb
Mariadb server |
Fri, 12 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was supposed to prevent them. This issue has been patched in versions 3.3.19 and 3.4.9. | |
| Title | MariaDB: mysql_real_escape_string() incorrectly handled big5 | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T20:02:12.617Z
Reserved: 2026-05-05T14:39:34.923Z
Link: CVE-2026-44172
Updated: 2026-06-12T20:02:08.825Z
Status : Analyzed
Published: 2026-06-12T18:16:34.123
Modified: 2026-06-16T19:35:39.710
Link: CVE-2026-44172
OpenCVE Enrichment
Updated: 2026-06-12T19:45:27Z