Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 984

debian логотип

CVE-2014-0065

почти 12 лет назад

Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9. ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2014-0064

почти 12 лет назад

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2014-0064

почти 12 лет назад

Multiple integer overflows in the path_in and other unspecified functi ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2014-0063

почти 12 лет назад

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065.

CVSS2: 6.5
EPSS: Средний
debian логотип

CVE-2014-0063

почти 12 лет назад

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0 ...

CVSS2: 6.5
EPSS: Средний
nvd логотип

CVE-2014-0062

почти 12 лет назад

Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.

CVSS2: 4.9
EPSS: Низкий
debian логотип

CVE-2014-0062

почти 12 лет назад

Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE ...

CVSS2: 4.9
EPSS: Низкий
nvd логотип

CVE-2014-0061

почти 12 лет назад

The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2014-0061

почти 12 лет назад

The validator functions for the procedural languages (PLs) in PostgreS ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2014-0060

почти 12 лет назад

PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-0065

Multiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9. ...

CVSS2: 6.5
4%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0064

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, which trigger a buffer overflow. NOTE: this identifier has been SPLIT due to different affected versions; use CVE-2014-2669 for the hstore vector.

CVSS2: 6.5
7%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0064

Multiple integer overflows in the path_in and other unspecified functi ...

CVSS2: 6.5
7%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0063

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via vectors related to an incorrect MAXDATELEN constant and datetime values involving (1) intervals, (2) timestamps, or (3) timezones, a different vulnerability than CVE-2014-0065.

CVSS2: 6.5
10%
Средний
почти 12 лет назад
debian логотип
CVE-2014-0063

Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0 ...

CVSS2: 6.5
10%
Средний
почти 12 лет назад
nvd логотип
CVE-2014-0062

Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthorized index or read portions of unauthorized tables by creating or deleting a table with the same name during the timing window.

CVSS2: 4.9
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0062

Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE ...

CVSS2: 4.9
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0061

The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1) defined in another language or (2) not allowed to be directly called by the user due to permissions.

CVSS2: 6.5
1%
Низкий
почти 12 лет назад
debian логотип
CVE-2014-0061

The validator functions for the procedural languages (PLs) in PostgreS ...

CVSS2: 6.5
1%
Низкий
почти 12 лет назад
nvd логотип
CVE-2014-0060

PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticated members of a role to add or remove arbitrary users to that role by calling the SET ROLE command before the associated GRANT command.

CVSS2: 4
1%
Низкий
почти 12 лет назад

Уязвимостей на страницу


Поделиться