PostgreSQL
by PostgreSQL
Source repositories
CVEs (179)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1410 | 0.00 | — | 0.00 | May 3, 2005 | The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service… | |||
| CVE-2005-0246 | 0.00 | — | 0.03 | May 2, 2005 | The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays. | |||
| CVE-2005-0247 | 0.00 | — | 0.04 | May 2, 2005 | Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement… | |||
| CVE-2005-0244 | 0.00 | — | 0.02 | May 2, 2005 | PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command. | |||
| CVE-2005-0227 | 0.00 | — | 0.01 | May 2, 2005 | PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension. | |||
| CVE-2004-0977 | 0.00 | — | 0.00 | Feb 9, 2005 | The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files. | |||
| CVE-2004-0547 | 0.00 | — | 0.03 | Aug 6, 2004 | Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). | |||
| CVE-2003-0901 | 0.00 | — | 0.05 | Nov 3, 2003 | Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. | |||
| CVE-2002-1397 | 0.00 | — | 0.03 | Jan 17, 2003 | Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. | |||
| CVE-2002-1399 | 0.00 | — | 0.02 | Jan 17, 2003 | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2). | |||
| CVE-2002-1400 | 0.00 | — | 0.04 | Jan 17, 2003 | Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. | |||
| CVE-2002-1401 | 0.00 | — | 0.02 | Jan 17, 2003 | Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. | |||
| CVE-2002-1398 | 0.00 | — | 0.01 | Jan 17, 2003 | Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input." | |||
| CVE-2002-1402 | 0.00 | — | 0.00 | Jan 17, 2003 | Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. | |||
| CVE-2002-1642 | 0.00 | — | 0.00 | Oct 3, 2002 | PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. | |||
| CVE-2002-0972 | 0.00 | — | 0.00 | Sep 24, 2002 | Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad. | |||
| CVE-2002-0802 | 0.00 | — | 0.01 | Aug 12, 2002 | The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks. | |||
| CVE-2001-1090 | 0.00 | — | 0.02 | Sep 10, 2001 | nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request. | |||
| CVE-1999-0862 | 0.00 | — | 0.00 | Dec 2, 1999 | Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. |
- CVE-2005-1410May 3, 2005risk 0.00cvss —epss 0.00
The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service…
- CVE-2005-0246May 2, 2005risk 0.00cvss —epss 0.03
The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.
- CVE-2005-0247May 2, 2005risk 0.00cvss —epss 0.04
Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement…
- CVE-2005-0244May 2, 2005risk 0.00cvss —epss 0.02
PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
- CVE-2005-0227May 2, 2005risk 0.00cvss —epss 0.01
PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.
- CVE-2004-0977Feb 9, 2005risk 0.00cvss —epss 0.00
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
- CVE-2004-0547Aug 6, 2004risk 0.00cvss —epss 0.03
Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).
- CVE-2003-0901Nov 3, 2003risk 0.00cvss —epss 0.05
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.
- CVE-2002-1397Jan 17, 2003risk 0.00cvss —epss 0.03
Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.
- CVE-2002-1399Jan 17, 2003risk 0.00cvss —epss 0.02
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2).
- CVE-2002-1400Jan 17, 2003risk 0.00cvss —epss 0.04
Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.
- CVE-2002-1401Jan 17, 2003risk 0.00cvss —epss 0.02
Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.
- CVE-2002-1398Jan 17, 2003risk 0.00cvss —epss 0.01
Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input."
- CVE-2002-1402Jan 17, 2003risk 0.00cvss —epss 0.00
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.
- CVE-2002-1642Oct 3, 2002risk 0.00cvss —epss 0.00
PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.
- CVE-2002-0972Sep 24, 2002risk 0.00cvss —epss 0.00
Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.
- CVE-2002-0802Aug 12, 2002risk 0.00cvss —epss 0.01
The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.
- CVE-2001-1090Sep 10, 2001risk 0.00cvss —epss 0.02
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
- CVE-1999-0862Dec 2, 1999risk 0.00cvss —epss 0.00
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.
Page 9 of 9