Логотип exploitDog
product: "postgresql"
Консоль
Логотип exploitDog

exploitDog

product: "postgresql"

Количество 984

Количество 984

rocky логотип

RLSA-2024:0951

больше 1 года назад

Important: postgresql security update

EPSS: Низкий
rocky логотип

RLSA-2024:0950

почти 2 года назад

Important: postgresql:15 security update

EPSS: Низкий
rocky логотип

RLSA-2023:0113

почти 3 года назад

Moderate: postgresql:10 security update

EPSS: Низкий
rocky логотип

RLSA-2022:7128

около 3 лет назад

Moderate: postgresql:12 security update

EPSS: Низкий
rocky логотип

RLSA-2022:4855

больше 3 лет назад

Important: postgresql:13 security update

EPSS: Низкий
rocky логотип

RLSA-2022:4807

больше 3 лет назад

Important: postgresql:12 security update

EPSS: Низкий
rocky логотип

RLSA-2022:4805

больше 3 лет назад

Important: postgresql:10 security update

EPSS: Низкий
rocky логотип

RLSA-2022:4771

больше 3 лет назад

Important: postgresql security update

EPSS: Низкий
rocky логотип

RLSA-2022:1891

больше 3 лет назад

Low: libpq security update

EPSS: Низкий
github логотип

GHSA-xvhg-pwg9-qp4r

больше 3 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xr8v-mf39-c8v7

больше 3 лет назад

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

EPSS: Низкий
github логотип

GHSA-xmm7-85wh-j3jf

больше 3 лет назад

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-xj65-3378-xxg3

больше 3 лет назад

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xgxp-9x8p-gcw4

почти 4 года назад

SQL Injection

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-xg92-g8h7-v7r4

больше 3 лет назад

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-xcqr-pm35-6p88

больше 3 лет назад

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

EPSS: Низкий
github логотип

GHSA-x9qg-qjqq-q3gj

больше 3 лет назад

PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.

EPSS: Низкий
github логотип

GHSA-x6pv-8pwj-29j9

больше 3 лет назад

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

EPSS: Низкий
github логотип

GHSA-wx2r-82wc-89gq

больше 3 лет назад

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."

EPSS: Низкий
github логотип

GHSA-wrg4-46g4-crg5

больше 3 лет назад

backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coercion of an unknown element to ANYARRAY.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:0951

Important: postgresql security update

1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:0950

Important: postgresql:15 security update

1%
Низкий
почти 2 года назад
rocky логотип
RLSA-2023:0113

Moderate: postgresql:10 security update

1%
Низкий
почти 3 года назад
rocky логотип
RLSA-2022:7128

Moderate: postgresql:12 security update

1%
Низкий
около 3 лет назад
rocky логотип
RLSA-2022:4855

Important: postgresql:13 security update

2%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:4807

Important: postgresql:12 security update

2%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:4805

Important: postgresql:10 security update

2%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:4771

Important: postgresql security update

2%
Низкий
больше 3 лет назад
rocky логотип
RLSA-2022:1891

Low: libpq security update

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xvhg-pwg9-qp4r

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xr8v-mf39-c8v7

PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a different vulnerability than CVE-2006-0553.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xmm7-85wh-j3jf

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.

CVSS3: 5.9
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xj65-3378-xxg3

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

CVSS3: 7.5
3%
Низкий
больше 3 лет назад
github логотип
GHSA-xgxp-9x8p-gcw4

SQL Injection

CVSS3: 8.8
23%
Средний
почти 4 года назад
github логотип
GHSA-xg92-g8h7-v7r4

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xcqr-pm35-6p88

Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and possibly execute arbitrary code, possibly as a result of an integer overflow.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-x9qg-qjqq-q3gj

PostgreSQL (pgsql) 7.4.x, 7.2.x, and other versions allows local users to load arbitrary shared libraries and execute code via the LOAD extension.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-x6pv-8pwj-29j9

PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-wx2r-82wc-89gq

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors related to the "contrib/pgcrypto functions."

1%
Низкий
больше 3 лет назад
github логотип
GHSA-wrg4-46g4-crg5

backend/parser/parse_coerce.c in PostgreSQL 7.4.1 through 7.4.14, 8.0.x before 8.0.9, and 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via a coercion of an unknown element to ANYARRAY.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу