Show filters
176 Total Results
Displaying 171-176 of 176
Sort by:
Attacker Value
Unknown
CVE-2002-0972
Disclosure Date: September 24, 2002 (last updated February 22, 2025)
Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.
0
Attacker Value
Unknown
CVE-2002-0802
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.
0
Attacker Value
Unknown
CVE-2001-1090
Disclosure Date: September 10, 2001 (last updated February 22, 2025)
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
0
Attacker Value
Unknown
CVE-2001-1089
Disclosure Date: September 10, 2001 (last updated February 22, 2025)
libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request.
0
Attacker Value
Unknown
CVE-2000-1199
Disclosure Date: August 31, 2001 (last updated February 22, 2025)
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.
0
Attacker Value
Unknown
CVE-1999-0862
Disclosure Date: December 02, 1999 (last updated February 22, 2025)
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.
0