Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161720202021202220232024202520262027202820292030

Недавние уязвимости PostgreSQL

Количество 970

ubuntu логотип

CVE-2019-10129

около 6 лет назад

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-10130

около 6 лет назад

A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2019-04641

около 6 лет назад

Уязвимость системы управления базами данных PostgreSQL, связанная с некорректным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 4.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1783-1

около 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1668-1

около 6 лет назад

Security update for postgresql96

EPSS: Низкий
nvd логотип

CVE-2019-10164

около 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-10164

около 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10164

около 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1687-1

около 6 лет назад

Security update for postgresql96

EPSS: Низкий
redhat логотип

CVE-2019-10164

около 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2019-10129

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

CVSS3: 6.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10130

A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excluding 9.6.13, 9.5.x up to, excluding 9.5.17. PostgreSQL maintains column statistics for tables. Certain statistics, such as histograms and lists of most common values, contain values taken from the column. PostgreSQL does not evaluate row security policies before consulting those statistics during query planning; an attacker can exploit this to read the most common values of certain columns. Affected columns are those for which the attacker has SELECT privilege and for which, in an ordinary query, row-level security prunes the set of rows visible to the attacker.

CVSS3: 4.3
0%
Низкий
около 6 лет назад
fstec логотип
BDU:2019-04641

Уязвимость системы управления базами данных PostgreSQL, связанная с некорректным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 4.3
0%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1783-1

Security update for postgresql10

5%
Низкий
около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1668-1

Security update for postgresql96

0%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
5%
Низкий
около 6 лет назад
debian логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are ...

CVSS3: 8.8
5%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
5%
Низкий
около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1687-1

Security update for postgresql96

0%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 7.5
5%
Низкий
около 6 лет назад

Уязвимостей на страницу


Поделиться