Postgresql
postgresql
186 CVEs • 3 products
Products (3)
Click to collapseToggle
Products (3)
Click to collapse
CVEs (186)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Postgresql Redhat4Decision Manager Enterprise LinuxPostgresql+1 moreJun 17, 2026 Mar 17, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQ...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of servic...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, all...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly ex...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and th...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for a...Show more |
3Canonical DebianPostgresql3Debian Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 20, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain...Show more |
3Canonical DebianPostgresql3Debian Linux Postgresql CommonUbuntu LinuxJun 17, 2026 Nov 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation. |
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory. |
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. |
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan. |
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY...Show more |
2Opensuse Postgresql2Leap PostgresqlJun 17, 2026 Jul 30, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Cert...Show more |
A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user ca...Show more |
4Fedoraproject OpensusePostgresql+1 more4Enterprise Linux FedoraLeap+1 moreJun 17, 2026 Jun 26, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpos...Show more |
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute arbitrary code in the context of the database's operating system user. T...Show more |
3Canonical PostgresqlRedhat3Enterprise Linux PostgresqlUbuntu LinuxNov 21, 2024 Nov 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpose-crafted trigger definition, an attacker can cause arbitrary SQL stat...Show more |
2Postgresql Redhat2Enterprise Linux Postgresql Jdbc DriverNov 21, 2024 Aug 30, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition...Show more |
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software. |