Filtered by vendor Postgresql
Subscribe
Total
171 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-1999-0862 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 2.1 LOW | N/A |
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. | |||||
CVE-2002-1642 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 7.2 HIGH | N/A |
PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. | |||||
CVE-2002-0972 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 4.6 MEDIUM | N/A |
Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad. | |||||
CVE-2003-0901 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 7.5 HIGH | N/A |
Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. | |||||
CVE-2000-1199 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 4.6 MEDIUM | N/A |
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases. | |||||
CVE-2002-0802 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 7.5 HIGH | N/A |
The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks. | |||||
CVE-2002-1401 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 6.5 MEDIUM | N/A |
Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. | |||||
CVE-2002-1657 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 5.0 MEDIUM | 7.5 HIGH |
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. | |||||
CVE-2004-0547 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 5.0 MEDIUM | N/A |
Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). | |||||
CVE-2002-1402 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 4.6 MEDIUM | N/A |
Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. | |||||
CVE-2002-1400 | 1 Postgresql | 1 Postgresql | 2024-02-28 | 7.5 HIGH | N/A |
Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. |