Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.40% | — | PostgresqlTrustix Secure Linux | 3/5/2005 | 16/6/2026 | The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other… | |
| Modificada | Media (6.5) | 3.5% | — | Postgresql | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in gram.y for PostgreSQL 8.0.1 and earlier may allow attackers to execute arbitrary code via (1) a large number of variables in a SQL statement being handled by the read_sql_construct function, (2) a large number of INTO variables in a SELECT statement being handled by the make_select_stmt… | |
| Modificada | Media (6.5) | 2.0% | — | Postgresql | 2/5/2005 | 16/6/2026 | PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command. | |
| Modificada | Media (5) | 2.6% | — | Postgresql | 2/5/2005 | 16/6/2026 | The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays. | |
| Modificada | Media (4.3) | 0.50% | — | Postgresql | 2/5/2005 | 16/6/2026 | PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension. | |
| Modificada | Baja (2.1) | 0.45% | — | PostgresqlMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Enterprise Linux+2 | 9/2/2005 | 16/6/2026 | The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Postgresql | 1/2/2005 | 16/6/2026 | Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247. | |
| Modificada | Media (5) | 2.7% | — | Postgresql | 6/8/2004 | 16/6/2026 | Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). | |
| Modificada | Alta (7.5) | 4.8% | — | Postgresql | 3/11/2003 | 16/6/2026 | Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.8% | — | Postgresql | 17/1/2003 | 16/6/2026 | Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow. | |
| Modificada | Media (6.5) | 2.2% | — | Postgresql | 17/1/2003 | 16/6/2026 | Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow. | |
| Modificada | Alta (10) | 1.8% | — | Postgresql | 17/1/2003 | 16/6/2026 | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which is processed as a different data type, as demonstrated using cash_out(2). | |
| Modificada | Media (4.6) | 0.48% | — | Postgresql | 17/1/2003 | 16/6/2026 | Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (4.6) | 0.54% | — | Postgresql | 17/1/2003 | 16/6/2026 | Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handling long datetime input." | |
| Modificada | Alta (7.5) | 3.9% | — | Postgresql | 17/1/2003 | 16/6/2026 | Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. | |
| Modificada | Alta (7.5) | 1.3% | — | Postgresql | 31/12/2002 | 16/6/2026 | PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. | |
| Modificada | Alta (7.2) | 0.43% | — | Postgresql | 3/10/2002 | 16/6/2026 | PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. | |
| Modificada | Media (4.6) | 0.49% | — | Postgresql | 24/9/2002 | 16/6/2026 | Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad. | |
| Modificada | Alta (7.5) | 1.1% | — | Postgresql | 12/8/2002 | 16/6/2026 | The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks. | |
| Modificada | Alta (7.5) | 1.6% | — | Alessandro Gardich NSS Postgresql | 10/9/2001 | 16/6/2026 | nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request. | |
| Modificada | Alta (7.5) | 1.6% | — | Alessandro Gardich NSS PostgresqlJoerg Wendland Libnss-pgsql | 10/9/2001 | 16/6/2026 | libnss-pgsql in nss-pgsql 0.9.0 and earlier allows remote attackers to execute arbitrary SQL queries by inserting SQL code into an HTTP request. | |
| Modificada | Media (4.6) | 0.91% | 💥 Exploit | Postgresql | 31/8/2001 | 16/6/2026 | PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases. | |
| Modificada | Baja (2.1) | 0.39% | — | Postgresql | 2/12/1999 | 16/6/2026 | Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file. |