Vulnerability

CVE-2016-5437

MEDIUM 4.9

CVE-2016-5437 is a medium-severity vulnerability (CVSS v3.0 4.9). As of 2026-10-09, 33 613 hosts in our data show software it affects on an open service in at least 15 countries.

Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Log.

Published
2016-07-21
Last modified
2026-06-17
CVSS score
4.9 CVSS v3.0
CVSS vector (v3.0)
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Exploit likelihood (EPSS)
2.2% in the next 30 days (higher than 82% of CVEs)

Exposure in our data

33 613 hosts

Hosts whose banner shows an affected software version on a service open at their latest check.

Not counted: 701 hosts with this CVE only from an older observation.

Not counted: 2 hosts where the software version is too vague to tell (only a major release).

Not counted: 1 060 more on distribution builds that may be patched (the distribution may have backported the fix without changing the version).

581 more hosts had it earlier (the software version has since changed or the service is gone).

Counted 2026-10-09 08:20 UTC

By country

China CN21 356
United States US3 862
Hong Kong HK1 602
South Korea KR1 218
Russia RU760
Japan JP729
Türkiye TR521
Singapore SG508
India IN449
Taiwan TW258
Brazil BR250
Malaysia MY225
Serbia RS223
Indonesia ID196
Canada CA173

Affected software seen

mysql 5.6.505 736
mysql 5.6.514 644
mysql 5.5.623 230
mysql 5.1.731 997
mysql 5.6.161 574
mysql 5.5.18.1770
mysql 5.6.25514
mysql 5.6.49498
mysql 5.7.12463
mysql 5.6.43376
mysql 5.6.44350
mysql 5.6.42349