|
121
|
-
9.0
|
HIGH
|
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated …
|
NVD-CWE-Other
|
CVE-2007-3280
|
cpe:2.3:a:postgresql:postgresql:8.1:*
|
|
|
|
|
2026-04-23 09:35
2007-06-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
-
6.0
|
MEDIUM
|
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users, when permitted…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2007-2138
|
cpe:2.3:a:postgresql:postgresql:*:*
|
7.4 8.0 8.1 8.2
|
|
|
7.3.19 7.4.17 8.0.13 8.1.9 8.2.4
|
2026-04-23 09:35
2007-04-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
-
8.5
|
HIGH
|
PostgreSQL 7.3 before 7.3.13, 7.4 before 7.4.16, 8.0 before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 allows attackers to disable certain checks for the data types of SQL function arguments, whi…
|
NVD-CWE-Other
|
CVE-2007-0555
|
cpe:2.3:a:postgresql:postgresql:*:*
|
7.3 7.4 8.0 8.1 8.2
|
|
|
7.3.18 7.4.16 8.0.11 8.1.7 8.2.2
|
2026-04-23 09:35
2007-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
-
6.6
|
MEDIUM
|
The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously made query plan," which allows remote authenticated…
|
NVD-CWE-Other
|
CVE-2007-0556
|
cpe:2.3:a:postgresql:postgresql:8.2:* cpe:2.3:a:postgresql:postgresql:8.2.1:* cpe:2.3:a:postgresql:postgresql:8.1…
|
|
|
|
|
2026-04-23 09:35
2007-02-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
-
4.0
|
MEDIUM
|
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which a…
|
NVD-CWE-Other
|
CVE-2006-5540
|
cpe:2.3:a:postgresql:postgresql:8.1:* cpe:2.3:a:postgresql:postgresql:8.1.4:* cpe:2.3:a:postgresql:postgresql:8.1…
|
|
|
|
|
2026-04-23 09:35
2006-10-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
-
4.0
|
MEDIUM
|
backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coerci…
|
NVD-CWE-noinfo
|
CVE-2006-5541
|
cpe:2.3:a:postgresql:postgresql:*:*
|
7.4 8.0.0 8.1.0
|
|
|
7.4.14 8.0.9 8.1.5
|
2026-04-23 09:35
2006-10-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
-
4.0
|
MEDIUM
|
backend/tcop/postgres.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) related to duration logging of V3-protocol Execute messages for …
|
NVD-CWE-Other
|
CVE-2006-5542
|
cpe:2.3:a:postgresql:postgresql:8.1:* cpe:2.3:a:postgresql:postgresql:8.1.4:* cpe:2.3:a:postgresql:postgresql:8.1…
|
|
|
|
|
2026-04-23 09:35
2006-10-27
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
-
7.5
|
HIGH
|
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in appl…
|
NVD-CWE-Other
|
CVE-2006-2313
|
cpe:2.3:a:postgresql:postgresql:8.1:* cpe:2.3:a:postgresql:postgresql:8.1.3:* cpe:2.3:a:postgresql:postgresql:8.1…
|
|
|
|
|
2018-10-19 01:39
2006-05-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
-
7.5
|
HIGH
|
PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in appl…
|
NVD-CWE-Other
|
CVE-2006-2314
|
cpe:2.3:a:postgresql:postgresql:8.1:* cpe:2.3:a:postgresql:postgresql:8.1.3:* cpe:2.3:a:postgresql:postgresql:8.1…
|
|
|
|
|
2018-10-19 01:39
2006-05-24
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
-
6.5
|
MEDIUM
|
PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a crafted SET ROLE to other database users, a different …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2006-0553
|
cpe:2.3:a:postgresql:postgresql:8.1.2:* cpe:2.3:a:postgresql:postgresql:8.1.1:* cpe:2.3:a:postgresql:postgresql:8…
|
|
|
|
|
2018-10-20 00:45
2006-02-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|