Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"
PostgreSQL

PostgreSQLсвободная объектно-реляционная система управления базами данных.

Релизный цикл, информация об уязвимостях

Продукт: PostgreSQL
Вендор: PostgreSQL

График релизов

141516171820212022202320242025202620272028202920302031

Недавние уязвимости PostgreSQL

Количество 984

debian логотип

CVE-2009-2943

больше 16 лет назад

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-2943

больше 16 лет назад

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2009-2943

больше 16 лет назад

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-3231

больше 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2009-3231

больше 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 befor ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2009-3230

больше 16 лет назад

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2009-3230

больше 16 лет назад

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8 ...

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2009-3229

больше 16 лет назад

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2009-3229

больше 16 лет назад

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8 ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2009-3231

больше 16 лет назад

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2009-2943

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL ...

CVSS2: 7.5
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2943

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 7.5
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2009-2943

The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringConn function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.

CVSS2: 5
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

CVSS2: 6.8
5%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 befor ...

CVSS2: 6.8
5%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3230

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.

CVSS2: 6.5
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3230

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8 ...

CVSS2: 6.5
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3229

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.

CVSS2: 4
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3229

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8 ...

CVSS2: 4
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

CVSS2: 6.8
5%
Низкий
больше 16 лет назад

Уязвимостей на страницу


Поделиться