Количество 43
Количество 43

RLSA-2021:5236
Moderate: postgresql:13 security update

RLSA-2021:5235
Moderate: postgresql:12 security update
ELSA-2021-5236
ELSA-2021-5236: postgresql:13 security update (MODERATE)
ELSA-2021-5235
ELSA-2021-5235: postgresql:12 security update (MODERATE)

SUSE-SU-2022:2958-1
Security update for postgresql12

CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

CVE-2021-3677
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbit ...

CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVE-2021-23214
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.

CVE-2021-23214
CVE-2021-23214
When the server is configured to use trust authentication with a clien ...

openSUSE-SU-2021:3256-1
Security update for postgresql12

openSUSE-SU-2021:3255-1
Security update for postgresql13

SUSE-SU-2021:3256-1
Security update for postgresql12

SUSE-SU-2021:3255-1
Security update for postgresql13

SUSE-SU-2021:3120-1
Security update for postgresql13
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | RLSA-2021:5236 Moderate: postgresql:13 security update | больше 3 лет назад | ||
![]() | RLSA-2021:5235 Moderate: postgresql:12 security update | больше 3 лет назад | ||
ELSA-2021-5236 ELSA-2021-5236: postgresql:13 security update (MODERATE) | больше 3 лет назад | |||
ELSA-2021-5235 ELSA-2021-5235: postgresql:12 security update (MODERATE) | больше 3 лет назад | |||
![]() | SUSE-SU-2022:2958-1 Security update for postgresql12 | почти 3 года назад | ||
![]() | CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад |
![]() | CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
![]() | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
CVE-2021-3677 A flaw was found in postgresql. A purpose-crafted query can read arbit ... | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
![]() | CVE-2021-23214 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2021-23214 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад |
![]() | CVE-2021-23214 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад |
![]() | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
CVE-2021-23214 When the server is configured to use trust authentication with a clien ... | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
![]() | openSUSE-SU-2021:3256-1 Security update for postgresql12 | 0% Низкий | больше 3 лет назад | |
![]() | openSUSE-SU-2021:3255-1 Security update for postgresql13 | 0% Низкий | больше 3 лет назад | |
![]() | SUSE-SU-2021:3256-1 Security update for postgresql12 | 0% Низкий | больше 3 лет назад | |
![]() | SUSE-SU-2021:3255-1 Security update for postgresql13 | 0% Низкий | больше 3 лет назад | |
![]() | SUSE-SU-2021:3120-1 Security update for postgresql13 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу