Skip to main content

Vendor archive

postgresql CVEs

Beta · best-effort

192 CVEs tagged to vendor postgresql14 Critical, 80 High, 85 Medium, 13 Low, 0 Unrated.

CVE-2005-0247

Published May 2, 2005

Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being han…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0245

Published Feb 1, 2005

Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which le…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0547

Published Aug 6, 2004

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0901

Published Nov 3, 2003

Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1397

Published Jan 17, 2003

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1398

Published Jan 17, 2003

Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vuln…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1399

Published Jan 17, 2003

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1400

Published Jan 17, 2003

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1401

Published Jan 17, 2003

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1402

Published Jan 17, 2003

Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arb…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1657

Published Dec 31, 2002

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1642

Published Oct 3, 2002

PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0972

Published Sep 24, 2002

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-0802

Published Aug 12, 2002

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape ch…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-1199

Published Aug 31, 2001

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0862

Published Dec 2, 1999

Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 176-192 of 192 CVEsPage 8 of 8