CVE-2007-3278
- EPSS 0.58%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host param...
- EPSS 2.4%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions tha...
- EPSS 56.64%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any l...
- EPSS 1.28%
- Veröffentlicht 24.04.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted to call a SECURITY DEFINER function, to gain the p...
CVE-2007-0555
- EPSS 1.84%
- Veröffentlicht 06.02.2007 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, which allows remote authenticated users to cause a den...
CVE-2007-0556
- EPSS 2%
- Veröffentlicht 06.02.2007 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated users to cause a denial of service (server crash) ...
- EPSS 1.62%
- Veröffentlicht 26.10.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index opt...
- EPSS 1.76%
- Veröffentlicht 26.10.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coercion of an unknown element to ANYARRAY.
- EPSS 1.62%
- Veröffentlicht 26.10.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
backend/tcop/postgres.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) related to duration logging of V3-protocol Execute messages for (1) COMMIT and (2) ROLLBACK SQL statements.
CVE-2006-2313
- EPSS 2.06%
- Veröffentlicht 24.05.2006 10:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications via invalid encodings of multibyte charact...