CVE Feed

    Dashboard / CVE / CVE-2024-41433

    CVE-2024-41433

    PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. NOTE: PingCAP maintains that the actual reproduction of this issue did not cause the security impact of service interruption to other users. They argue that this is a complex query bug and not a DoS vulnerability.

    Published:Sep 3, 2024
    Last Modified:Sep 4, 2025
    EPS:Sep 3, 2024
    EPSS Score:0.00227
    CVSS Score:9.8

    Affected Products

    Vendor
    Pingcap
    Product
    Tidb

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High