Back

CVE-2002-1397

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

Published: Jan 17, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (8)

Vendor Product Version
postgresql postgresql 6.3.2
postgresql postgresql 6.5.3
postgresql postgresql 7.0.3
postgresql postgresql 7.1
postgresql postgresql 7.1.1
postgresql postgresql 7.1.2
postgresql postgresql 7.1.3
postgresql postgresql 7.2

GitHub Security Advisory GHSA-83mr-c9w5-46g4

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.75%

Top 15% most likely to be exploited

Threat Score 30.8 / 100

Data Sources

NVD EPSS GitHub