Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 1 017

ubuntu логотип

CVE-2017-7546

больше 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2017-7548

больше 8 лет назад

PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2017-7546

больше 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 5.6
EPSS: Средний
redhat логотип

CVE-2017-7547

больше 8 лет назад

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2016-0768

почти 9 лет назад

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2016-0768

почти 9 лет назад

PostgreSQL PL/Java after 9.0 does not honor access controls on large o ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-0768

почти 9 лет назад

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7486

почти 9 лет назад

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-7486

почти 9 лет назад

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7485

почти 9 лет назад

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-7546

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 9.8
33%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-7548

PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.

CVSS3: 5.4
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-7546

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

CVSS3: 5.6
33%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-7547

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
nvd логотип
CVE-2016-0768

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

CVSS3: 7.5
0%
Низкий
почти 9 лет назад
debian логотип
CVE-2016-0768

PostgreSQL PL/Java after 9.0 does not honor access controls on large o ...

CVSS3: 7.5
0%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-0768

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

CVSS3: 7.5
0%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-7486

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
debian логотип
CVE-2017-7486

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg ...

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
nvd логотип
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

CVSS3: 5.9
1%
Низкий
почти 9 лет назад

Уязвимостей на страницу


Поделиться