Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 984

debian логотип

CVE-2020-1720

почти 6 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", whe ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2020-1720

почти 6 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
EPSS: Низкий
fstec логотип

BDU:2021-00082

почти 6 лет назад

Уязвимость компонента «ALTER ... DEPENDS ON EXTENSION» системы управления базами данных PostgreSQL, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0331-1

почти 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0589-1

почти 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0586-1

почти 6 лет назад

Security update for postgresql96

EPSS: Низкий
redhat логотип

CVE-2020-1720

почти 6 лет назад

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2015-0244

около 6 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2015-0244

около 6 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9. ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2015-0243

около 6 лет назад

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", whe ...

CVSS3: 3.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
0%
Низкий
почти 6 лет назад
fstec логотип
BDU:2021-00082

Уязвимость компонента «ALTER ... DEPENDS ON EXTENSION» системы управления базами данных PostgreSQL, позволяющая нарушителю оказать воздействие на целостность данных

CVSS3: 3.7
0%
Низкий
почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0331-1

Security update for postgresql10

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0589-1

Security update for postgresql10

0%
Низкий
почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:0586-1

Security update for postgresql96

0%
Низкий
почти 6 лет назад
redhat логотип
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database corruption. This issue affects PostgreSQL versions before 12.2, before 11.7, before 10.12 and before 9.6.17.

CVSS3: 3.1
0%
Низкий
почти 6 лет назад
nvd логотип
CVE-2015-0244

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
1%
Низкий
около 6 лет назад
debian логотип
CVE-2015-0244

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9. ...

CVSS3: 9.8
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2015-0243

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

CVSS3: 8.8
7%
Низкий
около 6 лет назад

Уязвимостей на страницу


Поделиться