Back

CVE-2005-1409

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

Published: May 3, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (28)

Vendor Product Version
postgresql postgresql 7.2.1
postgresql postgresql 7.2.2
postgresql postgresql 7.2.3
postgresql postgresql 7.2.4
postgresql postgresql 7.2.5
postgresql postgresql 7.2.6
postgresql postgresql 7.2.7
postgresql postgresql 7.3
postgresql postgresql 7.3.1
postgresql postgresql 7.3.2
postgresql postgresql 7.3.3
postgresql postgresql 7.3.4
postgresql postgresql 7.3.5
postgresql postgresql 7.3.6
postgresql postgresql 7.3.7
postgresql postgresql 7.3.8
postgresql postgresql 7.3.9
postgresql postgresql 7.4
postgresql postgresql 7.4.1
postgresql postgresql 7.4.2

…and 8 more

GitHub Security Advisory GHSA-4c8j-pqvg-527j

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.05%

Top 20% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub