Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Релизные элементы

KBВерсияБилдДата доступности
17.1017.10
17.917.9
17.817.8
17.717.7
17.617.6
17.517.5
17.417.4
17.317.3
17.217.2
17.117.1

Показывать по

Недавние уязвимости PostgreSQL

Количество 1 129

ubuntu логотип

CVE-2015-3166

больше 6 лет назад

The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-10211

почти 7 лет назад

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-10210

почти 7 лет назад

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2019-10209

почти 7 лет назад

Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

CVSS3: 2.2
EPSS: Низкий
debian логотип

CVE-2019-10209

почти 7 лет назад

Postgresql, versions 11.x before 11.5, is vulnerable to a memory discl ...

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2019-10208

почти 7 лет назад

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-10208

почти 7 лет назад

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5. ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-10209

почти 7 лет назад

Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2019-10208

почти 7 лет назад

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2019-03221

почти 7 лет назад

Уязвимость функции SECURITY DEFINER системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные SQL команды

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2015-3166

The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.

CVSS3: 9.8
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-10211

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10210

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.

CVSS3: 7
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10209

Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

CVSS3: 2.2
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10209

Postgresql, versions 11.x before 11.5, is vulnerable to a memory discl ...

CVSS3: 2.2
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-10208

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-10208

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5. ...

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10209

Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

CVSS3: 2.2
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-10208

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
fstec логотип
BDU:2019-03221

Уязвимость функции SECURITY DEFINER системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольные SQL команды

CVSS3: 8.8
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться