Количество 5
Количество 5

CVE-2020-10733
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

CVE-2020-10733
CVE-2020-10733
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided ...
GHSA-r2p6-249c-3h56
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.

BDU:2023-00612
Уязвимость установщика Windows installer системы управления базами данных PostgreSQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2020-10733 The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. | CVSS3: 7.3 | 0% Низкий | почти 5 лет назад |
![]() | CVSS3: 7.3 | 0% Низкий | почти 5 лет назад | |
CVE-2020-10733 The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided ... | CVSS3: 7.3 | 0% Низкий | почти 5 лет назад | |
GHSA-r2p6-249c-3h56 The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights. | 0% Низкий | около 3 лет назад | ||
![]() | BDU:2023-00612 Уязвимость установщика Windows installer системы управления базами данных PostgreSQL, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код | CVSS3: 6.7 | 0% Низкий | около 5 лет назад |
Уязвимостей на страницу