PostgreSQL — свободная объектно-реляционная система управления базами данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 974
CVE-2016-0768
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
CVE-2016-0768
PostgreSQL PL/Java after 9.0 does not honor access controls on large o ...
CVE-2016-0768
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
CVE-2017-7486
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
CVE-2017-7486
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg ...
CVE-2017-7485
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.
CVE-2017-7485
In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9 ...
CVE-2017-7484
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.
CVE-2017-7484
It was found that some selectivity estimation functions in PostgreSQL ...
CVE-2017-7486
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-0768 PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад | |
CVE-2016-0768 PostgreSQL PL/Java after 9.0 does not honor access controls on large o ... | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад | |
CVE-2016-0768 PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. | CVSS3: 7.5 | 0% Низкий | больше 8 лет назад | |
CVE-2017-7486 PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server. | CVSS3: 7.5 | 4% Низкий | больше 8 лет назад | |
CVE-2017-7486 PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg ... | CVSS3: 7.5 | 4% Низкий | больше 8 лет назад | |
CVE-2017-7485 In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server. | CVSS3: 5.9 | 1% Низкий | больше 8 лет назад | |
CVE-2017-7485 In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9 ... | CVSS3: 5.9 | 1% Низкий | больше 8 лет назад | |
CVE-2017-7484 It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access. | CVSS3: 7.5 | 1% Низкий | больше 8 лет назад | |
CVE-2017-7484 It was found that some selectivity estimation functions in PostgreSQL ... | CVSS3: 7.5 | 1% Низкий | больше 8 лет назад | |
CVE-2017-7486 PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server. | CVSS3: 7.5 | 4% Низкий | больше 8 лет назад |
Уязвимостей на страницу