V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-0064
DEB
Medium

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.…

CVSS
6.5
Medium
EPSS
0.05
p91
Published
2014-01-01
Updated
2014-01-01
Description

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector.

Tags · CWE
CWE-189
CWE-190
CAPEC-92
Affected products
Postgresql ≤ 8.4.19Postgresql
CVSS vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: S
Single
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.054 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
cfmeTracked
postgresqlTracked
postgresqlTracked
postgresql-8.4Tracked
postgresql-8.4Tracked
postgresql-9.1Tracked
postgresql-9.1Tracked
postgresql-9.3Tracked
postgresql-9.3Tracked
postgresql84Tracked
postgresql92-postgresqlTracked
postgresql92-postgresqlTracked
princeTracked
ruby193-rubygem-actionpackTracked
postgresql*Tracked
Source databases
DEB
CVE
RED
UBU