Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

131415161720202021202220232024202520262027202820292030

Недавние уязвимости PostgreSQL

Количество 970

ubuntu логотип

CVE-2013-0255

больше 12 лет назад

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

CVSS2: 6.8
EPSS: Низкий
fstec логотип

BDU:2014-00007

больше 12 лет назад

Уязвимость системы управления базами данных PostgreSQL, позволяющая злоумышленнику вызвать отказ в обслуживании или получить конфиденциальную информацию

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2013-0255

больше 12 лет назад

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-4575

больше 12 лет назад

The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-4575

больше 12 лет назад

The add_database function in objects.c in the pgbouncer pooler 1.5.2 f ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4575

больше 12 лет назад

The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-1618

почти 13 лет назад

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2012-1618

почти 13 лет назад

Interaction error in the PostgreSQL JDBC driver before 8.2, when used ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-1618

почти 13 лет назад

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-3489

почти 13 лет назад

The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2013-0255

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

CVSS2: 6.8
3%
Низкий
больше 12 лет назад
fstec логотип
BDU:2014-00007

Уязвимость системы управления базами данных PostgreSQL, позволяющая злоумышленнику вызвать отказ в обслуживании или получить конфиденциальную информацию

CVSS2: 6.8
3%
Низкий
больше 12 лет назад
redhat логотип
CVE-2013-0255

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the enum_recv function in backend/utils/adt/enum.c, which causes it to be invoked with incorrect arguments and allows remote authenticated users to cause a denial of service (server crash) or read sensitive process memory via a crafted SQL command, which triggers an array index error and an out-of-bounds read.

CVSS2: 5.5
3%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-4575

The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

CVSS2: 5
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-4575

The add_database function in objects.c in the pgbouncer pooler 1.5.2 f ...

CVSS2: 5
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-4575

The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.

CVSS2: 5
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-1618

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

CVSS2: 7.5
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-1618

Interaction error in the PostgreSQL JDBC driver before 8.2, when used ...

CVSS2: 7.5
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-1618

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

CVSS2: 7.5
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-3489

The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.

CVSS3: 6.5
1%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться