- EPSS 8.27%
- Veröffentlicht 25.08.2011 14:22:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext passwo...
CVE-2010-4015
- EPSS 5.3%
- Veröffentlicht 02.02.2011 01:00:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a deni...
- EPSS 1.62%
- Veröffentlicht 06.10.2010 17:00:16
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL use...
- EPSS 0.33%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code from the pltcl_modules table regardless of the tabl...
CVE-2010-1447
- EPSS 0.84%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2, allows ...
CVE-2010-1975
- EPSS 0.28%
- Veröffentlicht 19.05.2010 18:30:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove a...
CVE-2010-1169
- EPSS 1.3%
- Veröffentlicht 19.05.2010 18:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedures, which allows remote authenticated users, with da...
CVE-2010-0733
- EPSS 7.67%
- Veröffentlicht 19.03.2010 19:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related ...
CVE-2010-0442
- EPSS 16.19%
- Veröffentlicht 02.02.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in th...
CVE-2009-4034
- EPSS 1.11%
- Veröffentlicht 15.12.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 c...