Skip to content
Noroxi

PostgreSQL records

220 published records for vendor postgresql.

All records

220 records
  • PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers

    CriticalCVSS 9.8No exploitEPSS 62%

    postgresql · postgresqlAug 16, 2017

  • In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to

    HighCVSS 7.2WeaponizedEPSS 92%

    postgresql · postgresqlApr 1, 2019

  • A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.

    HighCVSS 8.8No exploitEPSS 46%

    postgresql · postgresqlNov 15, 2020

  • The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the

    CriticalCVSS 9.0WeaponizedEPSS 25%

    postgresql · postgresqlJun 19, 2007

  • Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to ca

    MediumCVSS 6.5WeaponizedEPSS 54%

    postgresql · postgresqlApr 4, 2013

  • postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...

    CriticalCVSS 9.8No exploitEPSS 5%

    postgresql · postgresqlNov 13, 2018

  • PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the

    CriticalCVSS 10.0No exploitEPSS 3%

    postgresql · postgresqlJun 19, 2007

  • PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly p

    CriticalCVSS 10.0No exploitEPSS 2%

    postgresql · postgresqlApr 4, 2013

  • PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tem

    CriticalCVSS 10.0No exploitEPSS 2%

    postgresql · postgresqlApr 4, 2013

  • Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wi

    CriticalCVSS 10.0No exploitEPSS 2%

    postgresql · postgresqlJan 17, 2003

  • A flaw was found in PostgreSQL.

    HighCVSS 8.8No exploitEPSS 16%

    postgresql · postgresqlAug 31, 2022

  • pgjdbc SQL Injection via line comment generation

    CriticalCVSS 9.8No exploitEPSS 5%

    postgresql · postgresql jdbc driverFeb 19, 2024

  • The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.

    CriticalCVSS 9.8No exploitEPSS 5%

    postgresql · postgresqlNov 20, 2019

  • PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erro

    CriticalCVSS 9.8No exploitEPSS 4%

    postgresql · postgresqlJan 27, 2020

  • Unchecked Class Instantiation when providing Plugin Classes

    CriticalCVSS 9.8No exploitEPSS 3%

    postgresql · postgresql jdbc driverFeb 2, 2022

  • In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary

    CriticalCVSS 9.8No exploitEPSS 3%

    postgresql · postgresql jdbc driverMar 10, 2022

  • Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpro

    CriticalCVSS 9.8No exploitEPSS 2%

    postgresql · postgresqlOct 29, 2019

  • CVE-2018-1058
    39Monitor

    A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.

    HighCVSS 8.8Proof of conceptEPSS 13%

    postgresql · postgresqlMar 2, 2018

  • CVE-2017-7547
    37Monitor

    PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attack

    HighCVSS 8.8No exploitEPSS 6%

    postgresql · postgresqlAug 16, 2017

  • CVE-2015-0241
    37Monitor

    The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow

    HighCVSS 8.8No exploitEPSS 6%

    postgresql · postgresqlJan 27, 2020

  • CVE-2015-0242
    37Monitor

    Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9

    HighCVSS 8.8No exploitEPSS 5%

    postgresql · postgresqlJan 27, 2020

  • CVE-2015-0243
    37Monitor

    Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and

    HighCVSS 8.8No exploitEPSS 5%

    postgresql · postgresqlJan 27, 2020

  • CVE-2016-3065
    37Monitor

    The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows atta

    CriticalCVSS 9.1No exploitEPSS 4%

    postgresql · postgresqlApr 11, 2016

  • CVE-2018-1115
    37Monitor

    postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow

    CriticalCVSS 9.1No exploitEPSS 4%

    postgresql · postgresqlMay 10, 2018

  • PostgreSQL PL/Perl environment variable changes execute arbitrary code

    HighCVSS 8.8No exploitEPSS 4%

    postgresql · postgresqlNov 14, 2024