Skip to main content

Vendor archive

postgresql CVEs

Beta · best-effort

200 CVEs tagged to vendor postgresql14 Critical, 85 High, 87 Medium, 14 Low, 0 Unrated.

CVE-2010-0733

Published Mar 19, 2010

Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (dae…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0442

Published Feb 2, 2010

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4136

Published Dec 15, 2009

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local st…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4034

Published Dec 15, 2009

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2943

Published Oct 22, 2009

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3230

Published Sep 17, 2009

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropr…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3229

Published Sep 17, 2009

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown)…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0922

Published Mar 17, 2009

PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4769

Published Jan 9, 2008

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticate…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6067

Published Jan 9, 2008

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 b…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6600

Published Jan 9, 2008

PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VAC…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3278

Published Jun 19, 2007

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3279

Published Jun 19, 2007

PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote atta…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3280

Published Jun 19, 2007

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows r…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0555

Published Feb 6, 2007

PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL fun…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0556

Published Feb 6, 2007

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5540

Published Oct 26, 2006

backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDAT…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5541

Published Oct 26, 2006

backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5542

Published Oct 26, 2006

backend/tcop/postgres.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) related to duration logging of V3-protocol E…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2313

Published May 24, 2006

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2314

Published May 24, 2006

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 200 CVEsPage 7 of 8