<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for mariadb</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2015:0743-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2015-03-03T00:49:26Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2015-03-03T00:49:26Z</InitialReleaseDate>
    <CurrentReleaseDate>2015-03-03T00:49:26Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for mariadb</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">mariadb was updated to version 10.0.16 to fix 40 security issues.

These security issues were fixed:
- CVE-2015-0411: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allowed remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption (bnc#915911).
- CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allowed remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381 (bnc#915911).
- CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allowed remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382 (bnc#915911).
- CVE-2015-0432: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allowed remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key (bnc#915911).
- CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allowed remote authenticated users to affect availability via vectors related to Server : InnoDB : DML (bnc#915911).
- CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allowed remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key (bnc#915911).
- CVE-2014-6507: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allowed remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML (bnc#915912).
- CVE-2014-6491: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allowed remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500 (bnc#915912).
- CVE-2014-6500: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allowed remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491 (bnc#915912).
- CVE-2014-6469: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and eariler and 5.6.20 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER (bnc#915912).
- CVE-2014-6555: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allowed remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML (bnc#915912).
- CVE-2014-6559: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allowed remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING (bnc#915912).
- CVE-2014-6494: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allowed remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496 (bnc#915912).
- CVE-2014-6496: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allowed remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494 (bnc#915912).
- CVE-2014-6464: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:INNODB DML FOREIGN KEYS (bnc#915912).
- CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allowed remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment (bnc#873351).
- CVE-2014-0195: The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h did not properly validate fragment lengths in DTLS ClientHello messages, which allowed remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment (bnc#880891).
- CVE-2014-0198: The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, did not properly manage a buffer pointer during certain recursive calls, which allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition (bnc#876282).
- CVE-2014-0221: The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allowed remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake (bnc#915913).
- CVE-2014-0224: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h did not properly restrict processing of ChangeCipherSpec messages, which allowed man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the 'CCS Injection' vulnerability (bnc#915913).
- CVE-2014-3470: The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allowed remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value (bnc#915913).
- CVE-2014-6474: Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED (bnc#915913).
- CVE-2014-6489: Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allowed remote authenticated users to affect integrity and availability via vectors related to SERVER:SP (bnc#915913).
- CVE-2014-6564: Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:INNODB FULLTEXT SEARCH DML (bnc#915913).
- CVE-2012-5615: Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allowed remote attackers to enumerate valid usernames (bnc#915913).
- CVE-2014-4274: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allowed local users to affect confidentiality, integrity, and availability via vectors related to SERVER:MyISAM (bnc#896400).
- CVE-2014-4287: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS (bnc#915913).
- CVE-2014-6463: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML (bnc#915913).
- CVE-2014-6478: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL (bnc#915913).
- CVE-2014-6484: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote authenticated users to affect availability via vectors related to SERVER:DML (bnc#915913).
- CVE-2014-6495: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL (bnc#915913).
- CVE-2014-6505: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE (bnc#915913).
- CVE-2014-6520: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier allowed remote authenticated users to affect availability via vectors related to SERVER:DDL (bnc#915913).
- CVE-2014-6530: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote authenticated users to affect confidentiality, integrity, and availability via vectors related to CLIENT:MYSQLDUMP (bnc#915913).
- CVE-2014-6551: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allowed local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN (bnc#915913).
- CVE-2015-0391: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allowed remote authenticated users to affect availability via vectors related to DDL (bnc#915913).
- CVE-2014-4258: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allowed remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC (bnc#915914).
- CVE-2014-4260: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allowed remote authenticated users to affect integrity and availability via vectors related to SRCHAR (bnc#915914).
- CVE-2014-2494: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allowed remote authenticated users to affect availability via vectors related to ENARC (bnc#915914).
- CVE-2014-4207: Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allowed remote authenticated users to affect availability via vectors related to SROPTZR (bnc#915914).

These non-security issues were fixed:
- Get query produced incorrect results in MariaDB 10.0.11 vs MySQL 5.5 - SLES12 (bnc#906194).
- After update to version 10.0.14 mariadb did not start - Job for mysql.service failed (bnc#911442).
- Fix crash when disk full situation is reached on alter table (bnc#904627).
- Allow md5 in FIPS mode (bnc#911556).
- Fixed a situation when bit and hex string literals unintentionally changed column names (bnc#919229).

Release notes: https://kb.askmonty.org/en/mariadb-10016-release-notes/
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-SLE-DESKTOP-12-2015-170,SUSE-SLE-SDK-12-2015-170,SUSE-SLE-SERVER-12-2015-170,SUSE-SLE-WE-12-2015-170</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      <Description>Link for SUSE-SU-2015:0743-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2015-April/001353.html</URL>
      <Description>E-Mail link for SUSE-SU-2015:0743-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/873351</URL>
      <Description>SUSE Bug 873351</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/876282</URL>
      <Description>SUSE Bug 876282</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/880891</URL>
      <Description>SUSE Bug 880891</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/896400</URL>
      <Description>SUSE Bug 896400</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/904627</URL>
      <Description>SUSE Bug 904627</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/906117</URL>
      <Description>SUSE Bug 906117</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/906194</URL>
      <Description>SUSE Bug 906194</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/911442</URL>
      <Description>SUSE Bug 911442</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/911556</URL>
      <Description>SUSE Bug 911556</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/915911</URL>
      <Description>SUSE Bug 915911</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/915912</URL>
      <Description>SUSE Bug 915912</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/915913</URL>
      <Description>SUSE Bug 915913</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/915914</URL>
      <Description>SUSE Bug 915914</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/919229</URL>
      <Description>SUSE Bug 919229</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2010-5298/</URL>
      <Description>SUSE CVE CVE-2010-5298 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2012-5615/</URL>
      <Description>SUSE CVE CVE-2012-5615 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0195/</URL>
      <Description>SUSE CVE CVE-2014-0195 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0198/</URL>
      <Description>SUSE CVE CVE-2014-0198 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0221/</URL>
      <Description>SUSE CVE CVE-2014-0221 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-0224/</URL>
      <Description>SUSE CVE CVE-2014-0224 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-2494/</URL>
      <Description>SUSE CVE CVE-2014-2494 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-3470/</URL>
      <Description>SUSE CVE CVE-2014-3470 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4207/</URL>
      <Description>SUSE CVE CVE-2014-4207 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4258/</URL>
      <Description>SUSE CVE CVE-2014-4258 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4260/</URL>
      <Description>SUSE CVE CVE-2014-4260 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4274/</URL>
      <Description>SUSE CVE CVE-2014-4274 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-4287/</URL>
      <Description>SUSE CVE CVE-2014-4287 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6463/</URL>
      <Description>SUSE CVE CVE-2014-6463 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6464/</URL>
      <Description>SUSE CVE CVE-2014-6464 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6469/</URL>
      <Description>SUSE CVE CVE-2014-6469 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6474/</URL>
      <Description>SUSE CVE CVE-2014-6474 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6478/</URL>
      <Description>SUSE CVE CVE-2014-6478 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6484/</URL>
      <Description>SUSE CVE CVE-2014-6484 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6489/</URL>
      <Description>SUSE CVE CVE-2014-6489 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6491/</URL>
      <Description>SUSE CVE CVE-2014-6491 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6494/</URL>
      <Description>SUSE CVE CVE-2014-6494 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6495/</URL>
      <Description>SUSE CVE CVE-2014-6495 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6496/</URL>
      <Description>SUSE CVE CVE-2014-6496 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6500/</URL>
      <Description>SUSE CVE CVE-2014-6500 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6505/</URL>
      <Description>SUSE CVE CVE-2014-6505 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6507/</URL>
      <Description>SUSE CVE CVE-2014-6507 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6520/</URL>
      <Description>SUSE CVE CVE-2014-6520 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6530/</URL>
      <Description>SUSE CVE CVE-2014-6530 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6551/</URL>
      <Description>SUSE CVE CVE-2014-6551 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6555/</URL>
      <Description>SUSE CVE CVE-2014-6555 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6559/</URL>
      <Description>SUSE CVE CVE-2014-6559 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6564/</URL>
      <Description>SUSE CVE CVE-2014-6564 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2014-6568/</URL>
      <Description>SUSE CVE CVE-2014-6568 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0374/</URL>
      <Description>SUSE CVE CVE-2015-0374 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0381/</URL>
      <Description>SUSE CVE CVE-2015-0381 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0382/</URL>
      <Description>SUSE CVE CVE-2015-0382 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0391/</URL>
      <Description>SUSE CVE CVE-2015-0391 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0411/</URL>
      <Description>SUSE CVE CVE-2015-0411 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2015-0432/</URL>
      <Description>SUSE CVE CVE-2015-0432 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12" CPE="cpe:/o:suse:sled:12">SUSE Linux Enterprise Desktop 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12" CPE="cpe:/o:suse:sles:12">SUSE Linux Enterprise Server 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12" CPE="cpe:/o:suse:sles_sap:12">SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12" CPE="cpe:/o:suse:sle-sdk:12">SUSE Linux Enterprise Software Development Kit 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 12">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12" CPE="cpe:/o:suse:sle-we:12">SUSE Linux Enterprise Workstation Extension 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libmysqlclient18-10.0.16-15.1">
      <FullProductName ProductID="libmysqlclient18-10.0.16-15.1">libmysqlclient18-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqlclient18-32bit-10.0.16-15.1">
      <FullProductName ProductID="libmysqlclient18-32bit-10.0.16-15.1">libmysqlclient18-32bit-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqlclient_r18-10.0.16-15.1">
      <FullProductName ProductID="libmysqlclient_r18-10.0.16-15.1">libmysqlclient_r18-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqlclient_r18-32bit-10.0.16-15.1">
      <FullProductName ProductID="libmysqlclient_r18-32bit-10.0.16-15.1">libmysqlclient_r18-32bit-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mariadb-10.0.16-15.1">
      <FullProductName ProductID="mariadb-10.0.16-15.1">mariadb-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mariadb-client-10.0.16-15.1">
      <FullProductName ProductID="mariadb-client-10.0.16-15.1">mariadb-client-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mariadb-errormessages-10.0.16-15.1">
      <FullProductName ProductID="mariadb-errormessages-10.0.16-15.1">mariadb-errormessages-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqlclient-devel-10.0.16-15.1">
      <FullProductName ProductID="libmysqlclient-devel-10.0.16-15.1">libmysqlclient-devel-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqld-devel-10.0.16-15.1">
      <FullProductName ProductID="libmysqld-devel-10.0.16-15.1">libmysqld-devel-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmysqld18-10.0.16-15.1">
      <FullProductName ProductID="libmysqld18-10.0.16-15.1">libmysqld18-10.0.16-15.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="mariadb-tools-10.0.16-15.1">
      <FullProductName ProductID="mariadb-tools-10.0.16-15.1">mariadb-tools-10.0.16-15.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libmysqlclient18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1">libmysqlclient18-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient18-32bit-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1">libmysqlclient18-32bit-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient_r18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1">libmysqlclient_r18-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient_r18-32bit-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1">libmysqlclient_r18-32bit-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1">mariadb-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-client-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1">mariadb-client-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-errormessages-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1">mariadb-errormessages-10.0.16-15.1 as a component of SUSE Linux Enterprise Desktop 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1">libmysqlclient18-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient18-32bit-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1">libmysqlclient18-32bit-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1">mariadb-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-client-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1">mariadb-client-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-errormessages-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1">mariadb-errormessages-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-tools-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1">mariadb-tools-10.0.16-15.1 as a component of SUSE Linux Enterprise Server 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1">libmysqlclient18-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient18-32bit-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1">libmysqlclient18-32bit-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1">mariadb-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-client-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1">mariadb-client-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-errormessages-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1">mariadb-errormessages-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="mariadb-tools-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1">mariadb-tools-10.0.16-15.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient-devel-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1">libmysqlclient-devel-10.0.16-15.1 as a component of SUSE Linux Enterprise Software Development Kit 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient_r18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1">libmysqlclient_r18-10.0.16-15.1 as a component of SUSE Linux Enterprise Software Development Kit 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqld-devel-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1">libmysqld-devel-10.0.16-15.1 as a component of SUSE Linux Enterprise Software Development Kit 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqld18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1">libmysqld18-10.0.16-15.1 as a component of SUSE Linux Enterprise Software Development Kit 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient_r18-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1">libmysqlclient_r18-10.0.16-15.1 as a component of SUSE Linux Enterprise Workstation Extension 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmysqlclient_r18-32bit-10.0.16-15.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 12">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1">libmysqlclient_r18-32bit-10.0.16-15.1 as a component of SUSE Linux Enterprise Workstation Extension 12</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.</Note>
    </Notes>
    <CVE>CVE-2010-5298</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2010-5298.html</URL>
        <Description>CVE-2010-5298</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/873351</URL>
        <Description>SUSE Bug 873351</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883126</URL>
        <Description>SUSE Bug 883126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.</Note>
    </Notes>
    <CVE>CVE-2012-5615</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2012-5615.html</URL>
        <Description>CVE-2012-5615</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/792440</URL>
        <Description>SUSE Bug 792440</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.</Note>
    </Notes>
    <CVE>CVE-2014-0195</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0195.html</URL>
        <Description>CVE-2014-0195</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.</Note>
    </Notes>
    <CVE>CVE-2014-0198</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0198.html</URL>
        <Description>CVE-2014-0198</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/876282</URL>
        <Description>SUSE Bug 876282</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.</Note>
    </Notes>
    <CVE>CVE-2014-0221</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0221.html</URL>
        <Description>CVE-2014-0221</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883126</URL>
        <Description>SUSE Bug 883126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905106</URL>
        <Description>SUSE Bug 905106</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.</Note>
    </Notes>
    <CVE>CVE-2014-0224</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-0224.html</URL>
        <Description>CVE-2014-0224</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1146657</URL>
        <Description>SUSE Bug 1146657</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/881743</URL>
        <Description>SUSE Bug 881743</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883126</URL>
        <Description>SUSE Bug 883126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/892403</URL>
        <Description>SUSE Bug 892403</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/903703</URL>
        <Description>SUSE Bug 903703</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905018</URL>
        <Description>SUSE Bug 905018</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905106</URL>
        <Description>SUSE Bug 905106</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914447</URL>
        <Description>SUSE Bug 914447</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/916239</URL>
        <Description>SUSE Bug 916239</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.</Note>
    </Notes>
    <CVE>CVE-2014-2494</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-2494.html</URL>
        <Description>CVE-2014-2494</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/887580</URL>
        <Description>SUSE Bug 887580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915914</URL>
        <Description>SUSE Bug 915914</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.</Note>
    </Notes>
    <CVE>CVE-2014-3470</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-3470.html</URL>
        <Description>CVE-2014-3470</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/880891</URL>
        <Description>SUSE Bug 880891</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/883126</URL>
        <Description>SUSE Bug 883126</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/885777</URL>
        <Description>SUSE Bug 885777</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/905106</URL>
        <Description>SUSE Bug 905106</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.</Note>
    </Notes>
    <CVE>CVE-2014-4207</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4207.html</URL>
        <Description>CVE-2014-4207</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/887580</URL>
        <Description>SUSE Bug 887580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915914</URL>
        <Description>SUSE Bug 915914</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC.</Note>
    </Notes>
    <CVE>CVE-2014-4258</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4258.html</URL>
        <Description>CVE-2014-4258</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/887580</URL>
        <Description>SUSE Bug 887580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915914</URL>
        <Description>SUSE Bug 915914</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR.</Note>
    </Notes>
    <CVE>CVE-2014-4260</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4260.html</URL>
        <Description>CVE-2014-4260</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/887580</URL>
        <Description>SUSE Bug 887580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915914</URL>
        <Description>SUSE Bug 915914</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to SERVER:MyISAM.</Note>
    </Notes>
    <CVE>CVE-2014-4274</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.6</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:C/I:C/A:C</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.1</BaseScore>
        <Vector>AV:L/AC:M/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4274.html</URL>
        <Description>CVE-2014-4274</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/857678</URL>
        <Description>SUSE Bug 857678</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/896400</URL>
        <Description>SUSE Bug 896400</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS.</Note>
    </Notes>
    <CVE>CVE-2014-4287</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-4287.html</URL>
        <Description>CVE-2014-4287</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.</Note>
    </Notes>
    <CVE>CVE-2014-6463</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.3</BaseScore>
        <Vector>AV:N/AC:L/Au:M/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6463.html</URL>
        <Description>CVE-2014-6463</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB DML FOREIGN KEYS.</Note>
    </Notes>
    <CVE>CVE-2014-6464</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6464.html</URL>
        <Description>CVE-2014-6464</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.</Note>
    </Notes>
    <CVE>CVE-2014-6469</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6469.html</URL>
        <Description>CVE-2014-6469</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.</Note>
    </Notes>
    <CVE>CVE-2014-6474</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.5</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6474.html</URL>
        <Description>CVE-2014-6474</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.</Note>
    </Notes>
    <CVE>CVE-2014-6478</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6478.html</URL>
        <Description>CVE-2014-6478</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:DML.</Note>
    </Notes>
    <CVE>CVE-2014-6484</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6484.html</URL>
        <Description>CVE-2014-6484</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.</Note>
    </Notes>
    <CVE>CVE-2014-6489</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6489.html</URL>
        <Description>CVE-2014-6489</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.</Note>
    </Notes>
    <CVE>CVE-2014-6491</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6491.html</URL>
        <Description>CVE-2014-6491</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.</Note>
    </Notes>
    <CVE>CVE-2014-6494</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6494.html</URL>
        <Description>CVE-2014-6494</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.</Note>
    </Notes>
    <CVE>CVE-2014-6495</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6495.html</URL>
        <Description>CVE-2014-6495</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.</Note>
    </Notes>
    <CVE>CVE-2014-6496</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6496.html</URL>
        <Description>CVE-2014-6496</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.</Note>
    </Notes>
    <CVE>CVE-2014-6500</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6500.html</URL>
        <Description>CVE-2014-6500</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE.</Note>
    </Notes>
    <CVE>CVE-2014-6505</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6505.html</URL>
        <Description>CVE-2014-6505</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.</Note>
    </Notes>
    <CVE>CVE-2014-6507</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6507.html</URL>
        <Description>CVE-2014-6507</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:DDL.</Note>
    </Notes>
    <CVE>CVE-2014-6520</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6520.html</URL>
        <Description>CVE-2014-6520</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="29">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to CLIENT:MYSQLDUMP.</Note>
    </Notes>
    <CVE>CVE-2014-6530</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6530.html</URL>
        <Description>CVE-2014-6530</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="30">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.</Note>
    </Notes>
    <CVE>CVE-2014-6551</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>2.1</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6551.html</URL>
        <Description>CVE-2014-6551</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="31">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.</Note>
    </Notes>
    <CVE>CVE-2014-6555</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6555.html</URL>
        <Description>CVE-2014-6555</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="32">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.</Note>
    </Notes>
    <CVE>CVE-2014-6559</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6559.html</URL>
        <Description>CVE-2014-6559</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915912</URL>
        <Description>SUSE Bug 915912</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="33">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB FULLTEXT SEARCH DML.</Note>
    </Notes>
    <CVE>CVE-2014-6564</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6564.html</URL>
        <Description>CVE-2014-6564</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/901237</URL>
        <Description>SUSE Bug 901237</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="34">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.</Note>
    </Notes>
    <CVE>CVE-2014-6568</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.5</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2014-6568.html</URL>
        <Description>CVE-2014-6568</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="35">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.</Note>
    </Notes>
    <CVE>CVE-2015-0374</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.5</BaseScore>
        <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0374.html</URL>
        <Description>CVE-2015-0374</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="36">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.</Note>
    </Notes>
    <CVE>CVE-2015-0381</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0381.html</URL>
        <Description>CVE-2015-0381</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="37">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.</Note>
    </Notes>
    <CVE>CVE-2015-0382</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0382.html</URL>
        <Description>CVE-2015-0382</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="38">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.</Note>
    </Notes>
    <CVE>CVE-2015-0391</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0391.html</URL>
        <Description>CVE-2015-0391</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915913</URL>
        <Description>SUSE Bug 915913</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="39">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.</Note>
    </Notes>
    <CVE>CVE-2015-0411</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>7.5</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0411.html</URL>
        <Description>CVE-2015-0411</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="40">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.</Note>
    </Notes>
    <CVE>CVE-2015-0432</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:libmysqlclient18-32bit-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-client-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-errormessages-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12:mariadb-tools-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld-devel-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12:libmysqld18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-10.0.16-15.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 12:libmysqlclient_r18-32bit-10.0.16-15.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2015/suse-su-20150743-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2015-0432.html</URL>
        <Description>CVE-2015-0432</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/914058</URL>
        <Description>SUSE Bug 914058</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/915911</URL>
        <Description>SUSE Bug 915911</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
