Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161718202020212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 974

github логотип

GHSA-5px2-4wrg-vxxc

больше 3 лет назад

Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.

EPSS: Низкий
github логотип

GHSA-83mr-c9w5-46g4

больше 3 лет назад

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

EPSS: Низкий
github логотип

GHSA-h9vf-mxh9-5cxv

больше 3 лет назад

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.

EPSS: Низкий
github логотип

GHSA-xcqr-pm35-6p88

больше 3 лет назад

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

EPSS: Низкий
github логотип

GHSA-m4fw-hwf8-whx3

больше 3 лет назад

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

EPSS: Низкий
github логотип

GHSA-8w3r-p439-x2rh

больше 3 лет назад

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.

EPSS: Низкий
github логотип

GHSA-9ccp-985w-grj6

больше 3 лет назад

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

EPSS: Низкий
github логотип

GHSA-p674-c6w9-wwgg

больше 3 лет назад

Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

EPSS: Низкий
github логотип

GHSA-6j7m-4j6m-84cw

больше 3 лет назад

The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.

EPSS: Низкий
github логотип

GHSA-83x8-fwcx-3pmf

больше 3 лет назад

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-5px2-4wrg-vxxc

Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-83mr-c9w5-46g4

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly triggering an integer signedness error or buffer overflow.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-h9vf-mxh9-5cxv

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-xcqr-pm35-6p88

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m4fw-hwf8-whx3

Buffer overflows in PostgreSQL 7.2 allow attackers to cause a denial of service and possibly execute arbitrary code via long arguments to the functions (1) lpad or (2) rpad.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8w3r-p439-x2rh

The multibyte support in PostgreSQL 6.5.x with SQL_ASCII encoding consumes an extra character when processing a character that cannot be converted, which could remove an escape character from the query and make the application subject to SQL injection attacks.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9ccp-985w-grj6

PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-p674-c6w9-wwgg

Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6j7m-4j6m-84cw

The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-83x8-fwcx-3pmf

Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash).

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться