Vulnerability index

Browse CVEs

144 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 10.0 CVE-2007-3279 PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do… PostgreSQL Mitigation only Fix from $1,9502007-06-19 HIGH 9.0 CVE-2007-3280EPSS 25% The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C progra… PostgreSQL Mitigation only Fix from $1,9502007-06-19 MEDIUM 6.9 CVE-2007-3278 PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows re… PostgreSQL 7.3.21 / 7.4.19+ Fix from $1,6002007-06-19 MEDIUM 6.0 CVE-2007-2138 Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4… PostgreSQL 7.3.19 / 7.4.17+ Fix from $1,6002007-04-24 HIGH 8.5 CVE-2007-0555 PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks… PostgreSQL 7.3.18 / 7.4.16+ Fix from $1,9502007-02-06 MEDIUM 6.6 CVE-2007-0556 The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously m… PostgreSQL Mitigation only Fix from $1,6002007-02-06 HIGH 7.5 CVE-2006-2313 PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers … PostgreSQL Patch available Fix from $1,9502006-05-24 HIGH 7.5 CVE-2006-2314 PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers … PostgreSQL Patch available Fix from $1,9502006-05-24 MEDIUM 6.5 CVE-2006-0553 PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a craf… PostgreSQL Patch available Fix from $1,6002006-02-14 MEDIUM 5.0 CVE-2006-0105 PostgreSQL 8.0.x before 8.0.6 and 8.1.x before 8.1.2, when running on Windows, allows remote attackers to cause a denial of service (postmaster exit … PostgreSQL Patch available Fix from $1,6002006-01-10 HIGH 7.5 CVE-2005-1409 PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those f… PostgreSQL Patch available Fix from $1,9502005-05-03 MEDIUM 6.5 CVE-2005-0244 PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command. PostgreSQL Patch available Fix from $1,6002005-05-02 MEDIUM 6.5 CVE-2005-0247 Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variable… PostgreSQL Patch available Fix from $1,6002005-05-02 MEDIUM 5.0 CVE-2005-0246 The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays. PostgreSQL 7.3.9 / 7.4.7+ Fix from $1,6002005-05-02 HIGH 7.5 CVE-2005-0245EPSS 14% Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcurs… PostgreSQL 7.3.10 / 7.4.7+ Fix from $1,9502005-02-01 MEDIUM 5.0 CVE-2004-0547 Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). PostgreSQL Patch available Fix from $1,6002004-08-06 HIGH 7.5 CVE-2003-0901 Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. PostgreSQL Patch available Fix from $1,9502003-11-03 HIGH 10.0 CVE-2002-1399 Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow… PostgreSQL Mitigation only Fix from $1,9502003-01-17 HIGH 7.5 CVE-2002-1397 Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitr… PostgreSQL Mitigation only Fix from $1,9502003-01-17 HIGH 7.5 CVE-2002-1400 Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to gen… PostgreSQL Mitigation only Fix from $1,9502003-01-17 MEDIUM 6.5 CVE-2002-1401 Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier all… PostgreSQL Patch available Fix from $1,6002003-01-17 HIGH 7.5 CVE-2002-1657 PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force at… PostgreSQL Mitigation only Fix from $1,9502002-12-31 HIGH 7.2 CVE-2002-1642 PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM comma… PostgreSQL Patch available Fix from $1,9502002-10-03 HIGH 7.5 CVE-2002-0802 The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, w… PostgreSQL Mitigation only Fix from $1,9502002-08-12