Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161718202020212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 974

debian логотип

CVE-2020-1720

больше 5 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", whe ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2020-1720

больше 5 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2021-00082

больше 5 лет назад

Уязвимость компонента «ALTER ... DEPENDS ON EXTENSION» системы управления базами данных PostgreSQL, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0331-1

больше 5 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0589-1

больше 5 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0586-1

больше 5 лет назад

Security update for postgresql96

EPSS: Низкий
redhat логотип

CVE-2020-1720

больше 5 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2015-0244

почти 6 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-0244

почти 6 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9. ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-0243

почти 6 лет назад

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", whe ...

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
fstec логотип
BDU:2021-00082

Уязвимость компонента «ALTER ... DEPENDS ON EXTENSION» системы управления базами данных PostgreSQL, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.7
0%
Низкий
больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0331-1

Security update for postgresql10

0%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0589-1

Security update for postgresql10

0%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0586-1

Security update for postgresql96

0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2015-0244

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2015-0244

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9. ...

CVSS3: 9.8
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2015-0243

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

CVSS3: 8.8
3%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться