Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161718202020212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 974

debian логотип

CVE-2019-10164

больше 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10164

больше 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1687-1

больше 6 лет назад

Security update for postgresql96

EPSS: Низкий
redhat логотип

CVE-2019-10164

больше 6 лет назад

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2019-02385

больше 6 лет назад

Множественные уязвимости системы управления базами данных PostgreSQL, вызванные переполнением буфера на стеке, позволяющие нарушителю выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1578-1

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1511-1

больше 6 лет назад

Security update for postgresql10

EPSS: Низкий
redhat логотип

CVE-2019-10129

больше 6 лет назад

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-10128

больше 6 лет назад

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2019-10127

больше 6 лет назад

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are ...

CVSS3: 8.8
5%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 8.8
5%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1687-1

Security update for postgresql96

0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL operating system account.

CVSS3: 7.5
5%
Низкий
больше 6 лет назад
fstec логотип
BDU:2019-02385

Множественные уязвимости системы управления базами данных PostgreSQL, вызванные переполнением буфера на стеке, позволяющие нарушителю выполнить произвольный код

CVSS3: 7.5
5%
Низкий
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1578-1

Security update for postgresql10

0%
Низкий
больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1511-1

Security update for postgresql10

0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10129

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any user can create a partitioned table suitable for this attack. (Exploit prerequisites are the same as for CVE-2018-1052).

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10128

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, this allows a local attacker to read arbitrary data directory files, essentially bypassing database-imposed read access limitations. In plausible non-default configurations, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code.

CVSS3: 7
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-10127

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In the default configuration, an attacker having both an unprivileged Windows account and an unprivileged PostgreSQL account can cause the PostgreSQL service account to execute arbitrary code. An attacker having only the unprivileged Windows account can read arbitrary data directory files, essentially bypassing database-imposed read access limitations. An attacker having only the unprivileged Windows account can also delete certain data directory files.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться