Vulnerability index

Browse CVEs

144 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PostgreSQL HIGH 10.0
CVE-2007-3279

PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do…

Mitigation only
Fix from $1,950 2007-06-19
PostgreSQL HIGH 9.0
CVE-2007-3280EPSS 25%

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C progra…

Mitigation only
Fix from $1,950 2007-06-19
PostgreSQL MEDIUM 6.9
CVE-2007-3278

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows re…

Fix: 7.3.21 / 7.4.19+
Fix from $1,600 2007-06-19
PostgreSQL MEDIUM 6.0
CVE-2007-2138

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4…

Fix: 7.3.19 / 7.4.17+
Fix from $1,600 2007-04-24
PostgreSQL HIGH 8.5
CVE-2007-0555

PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks…

Fix: 7.3.18 / 7.4.16+
Fix from $1,950 2007-02-06
PostgreSQL MEDIUM 6.6
CVE-2007-0556

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously m…

Mitigation only
Fix from $1,600 2007-02-06
PostgreSQL HIGH 7.5
CVE-2006-2313

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers …

Patch available
Fix from $1,950 2006-05-24
PostgreSQL HIGH 7.5
CVE-2006-2314

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers …

Patch available
Fix from $1,950 2006-05-24
PostgreSQL MEDIUM 6.5
CVE-2006-0553

PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a craf…

Patch available
Fix from $1,600 2006-02-14
PostgreSQL MEDIUM 5.0
CVE-2006-0105

PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit …

Patch available
Fix from $1,600 2006-01-10
PostgreSQL HIGH 7.5
CVE-2005-1409

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those f…

Patch available
Fix from $1,950 2005-05-03
PostgreSQL MEDIUM 6.5
CVE-2005-0244

PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.

Patch available
Fix from $1,600 2005-05-02
PostgreSQL MEDIUM 6.5
CVE-2005-0247

Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variable…

Patch available
Fix from $1,600 2005-05-02
PostgreSQL MEDIUM 5.0
CVE-2005-0246

The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.

Fix: 7.3.9 / 7.4.7+
Fix from $1,600 2005-05-02
PostgreSQL HIGH 7.5
CVE-2005-0245EPSS 14%

Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcurs…

Fix: 7.3.10 / 7.4.7+
Fix from $1,950 2005-02-01
PostgreSQL MEDIUM 5.0
CVE-2004-0547

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

Patch available
Fix from $1,600 2004-08-06
PostgreSQL HIGH 7.5
CVE-2003-0901

Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code.

Patch available
Fix from $1,950 2003-11-03
PostgreSQL HIGH 10.0
CVE-2002-1399

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow…

Mitigation only
Fix from $1,950 2003-01-17
PostgreSQL HIGH 7.5
CVE-2002-1397

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitr…

Mitigation only
Fix from $1,950 2003-01-17
PostgreSQL HIGH 7.5
CVE-2002-1400

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to gen…

Mitigation only
Fix from $1,950 2003-01-17
PostgreSQL MEDIUM 6.5
CVE-2002-1401

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier all…

Patch available
Fix from $1,600 2003-01-17
PostgreSQL HIGH 7.5
CVE-2002-1657

PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force at…

Mitigation only
Fix from $1,950 2002-12-31
PostgreSQL HIGH 7.2
CVE-2002-1642

PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM comma…

Patch available
Fix from $1,950 2002-10-03
PostgreSQL HIGH 7.5
CVE-2002-0802

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, w…

Mitigation only
Fix from $1,950 2002-08-12