Vulnerabilities > Postgresql > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2003-11-03 | CVE-2003-0901 | Buffer Overflow vulnerability in PostgreSQL To_Ascii() Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. | 7.5 |
2003-01-17 | CVE-2002-1400 | Unspecified vulnerability in Postgresql Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. | 7.5 |
2003-01-17 | CVE-2002-1397 | Buffer Overflow vulnerability in PostgreSQL cash_words Function Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. | 7.5 |
2002-12-31 | CVE-2002-1657 | Use of Password Hash With Insufficient Computational Effort vulnerability in Postgresql 7.3.19 PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. | 7.5 |
2002-10-03 | CVE-2002-1642 | Unspecified vulnerability in Postgresql 7.2/7.2.1/7.2.2 PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. | 7.2 |
2002-08-12 | CVE-2002-0802 | SQL-Injection vulnerability in Postgresql 6.5.0 The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks. | 7.5 |