CVEs (175)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. |
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan. |
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY...Show more |
2Opensuse Postgresql2Leap PostgresqlJun 17, 2026 Jul 30, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Cert...Show more |
A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user ca...Show more |
4Fedoraproject OpensusePostgresql+1 more4Enterprise Linux FedoraLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpos...Show more |
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. T...Show more |
3Canonical PostgresqlRedhat3Enterprise Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more |
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software. |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Aug 9, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "...Show more |
4Canonical DebianPostgresql+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Aug 9, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" co...Show more |
2Opensuse Postgresql2Leap PostgresqlNov 21, 2024 May 10, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, a...Show more |
3Canonical PostgresqlRedhat3Cloudforms PostgresqlUbuntu LinuxNov 21, 2024 Mar 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the databa...Show more |
2Postgresql Suse2Postgresql Suse Linux Enterprise ServerNov 21, 2024 Mar 1, 2018 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. |
4Canonical DebianPostgresql+1 more4Cloudforms Debian LinuxPostgresql+1 moreNov 21, 2024 Feb 9, 2018 N/A· v4 7.0 HIGH· v3 3.3 LOW· v2 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under um...Show more |
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned tabl...Show more |
PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effecti...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables wh...Show more |
2Debian Postgresql2Debian Linux PostgresqlMay 13, 2026 Nov 22, 2017 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or dis...Show more |
The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handle...Show more |