Записи PostgreSQL
220 опубликованных записей вендора postgresql.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 3 · 1,4 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 86,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls20
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-20 Improper Input Validation7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
220 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2017-7546Эксплойта нет | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackerspostgresql · postgresql · CWE-287 | Критическая9,8 | — | 61,6 % | 16 авг. 2017 г. |
55В плане | CVE-2019-9193Готовый эксплойт | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to postgresql · postgresql · CWE-78 | Высокая7,2 | — | 91,7 % | 1 апр. 2019 г. |
49В плане | CVE-2020-25695Эксплойта нет | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.postgresql · postgresql · CWE-89 | Высокая8,8 | — | 46,4 % | 15 нояб. 2020 г. |
44В плане | CVE-2007-3280Готовый эксплойт | The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on thepostgresql · postgresql | Критическая9,0 | — | 25,5 % | 19 июн. 2007 г. |
42В плане | CVE-2013-1899Готовый эксплойт | Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to capostgresql · postgresql · CWE-94 | Средняя6,5 | — | 54,3 % | 4 апр. 2013 г. |
41В плане | CVE-2018-16850Эксплойта нет | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...postgresql · postgresql · CWE-89 | Критическая9,8 | — | 5,2 % | 13 нояб. 2018 г. |
41В плане | CVE-2007-3279Эксплойта нет | PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the postgresql · postgresql | Критическая10,0 | — | 2,6 % | 19 июн. 2007 г. |
41В плане | CVE-2013-1903Эксплойта нет | PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly ppostgresql · postgresql · CWE-264 | Критическая10,0 | — | 2,2 % | 4 апр. 2013 г. |
41В плане | CVE-2013-1902Эксплойта нет | PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tempostgresql · postgresql | Критическая10,0 | — | 2,2 % | 4 апр. 2013 г. |
41В плане | CVE-2002-1399Эксплойта нет | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wipostgresql · postgresql | Критическая10,0 | — | 1,8 % | 17 янв. 2003 г. |
40В плане | CVE-2022-1552Эксплойта нет | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | Высокая8,8 | — | 16,0 % | 31 авг. 2022 г. |
40В плане | CVE-2024-1597Эксплойта нет | pgjdbc SQL Injection via line comment generationpostgresql · postgresql jdbc driver · CWE-89 | Критическая9,8 | — | 4,8 % | 19 февр. 2024 г. |
40В плане | CVE-2015-3166Эксплойта нет | The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.postgresql · postgresql · CWE-119 | Критическая9,8 | — | 4,6 % | 20 нояб. 2019 г. |
40В плане | CVE-2015-0244Эксплойта нет | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erropostgresql · postgresql · CWE-89 | Критическая9,8 | — | 4,4 % | 27 янв. 2020 г. |
40В плане | CVE-2022-21724Эксплойта нет | Unchecked Class Instantiation when providing Plugin Classespostgresql · postgresql jdbc driver · CWE-665 | Критическая9,8 | — | 3,1 % | 2 февр. 2022 г. |
40В плане | CVE-2022-26520Эксплойта нет | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary postgresql · postgresql jdbc driver | Критическая9,8 | — | 3,0 % | 10 мар. 2022 г. |
40В плане | CVE-2019-10211Эксплойта нет | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpropostgresql · postgresql · CWE-94 | Критическая9,8 | — | 1,8 % | 29 окт. 2019 г. |
39Наблюдать | CVE-2018-1058Proof of concept | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.postgresql · postgresql · CWE-20 | Высокая8,8 | — | 13,1 % | 2 мар. 2018 г. |
37Наблюдать | CVE-2017-7547Эксплойта нет | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackpostgresql · postgresql · CWE-522 | Высокая8,8 | — | 5,6 % | 16 авг. 2017 г. |
37Наблюдать | CVE-2015-0241Эксплойта нет | The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allowpostgresql · postgresql · CWE-120 | Высокая8,8 | — | 5,5 % | 27 янв. 2020 г. |
37Наблюдать | CVE-2015-0242Эксплойта нет | Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9postgresql · postgresql · CWE-787 | Высокая8,8 | — | 5,1 % | 27 янв. 2020 г. |
37Наблюдать | CVE-2015-0243Эксплойта нет | Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, andpostgresql · postgresql · CWE-120 | Высокая8,8 | — | 5,1 % | 27 янв. 2020 г. |
37Наблюдать | CVE-2016-3065Эксплойта нет | The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attapostgresql · postgresql · CWE-264 | Критическая9,1 | — | 4,1 % | 11 апр. 2016 г. |
37Наблюдать | CVE-2018-1115Эксплойта нет | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow postgresql · postgresql · CWE-732 | Критическая9,1 | — | 3,9 % | 10 мая 2018 г. |
36Наблюдать | CVE-2024-10979Эксплойта нет | PostgreSQL PL/Perl environment variable changes execute arbitrary codepostgresql · postgresql · CWE-15 | Высокая8,8 | — | 4,4 % | 14 нояб. 2024 г. |
- CVE-2017-754657В плане
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers
КритическаяCVSS 9,8Эксплойта нетEPSS 62 %postgresql · postgresql16 авг. 2017 г.
- CVE-2019-919355В плане
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to
ВысокаяCVSS 7,2Готовый эксплойтEPSS 92 %postgresql · postgresql1 апр. 2019 г.
- CVE-2020-2569549В плане
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
ВысокаяCVSS 8,8Эксплойта нетEPSS 46 %postgresql · postgresql15 нояб. 2020 г.
- CVE-2007-328044В плане
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the
КритическаяCVSS 9,0Готовый эксплойтEPSS 25 %postgresql · postgresql19 июн. 2007 г.
- CVE-2013-189942В плане
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to ca
СредняяCVSS 6,5Готовый эксплойтEPSS 54 %postgresql · postgresql4 апр. 2013 г.
- CVE-2018-1685041В плане
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %postgresql · postgresql13 нояб. 2018 г.
- CVE-2007-327941В плане
PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %postgresql · postgresql19 июн. 2007 г.
- CVE-2013-190341В плане
PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly p
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %postgresql · postgresql4 апр. 2013 г.
- CVE-2013-190241В плане
PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tem
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %postgresql · postgresql4 апр. 2013 г.
- CVE-2002-139941В плане
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wi
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %postgresql · postgresql17 янв. 2003 г.
- CVE-2022-155240В плане
A flaw was found in PostgreSQL.
ВысокаяCVSS 8,8Эксплойта нетEPSS 16 %postgresql · postgresql31 авг. 2022 г.
- CVE-2024-159740В плане
pgjdbc SQL Injection via line comment generation
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %postgresql · postgresql jdbc driver19 февр. 2024 г.
- CVE-2015-316640В плане
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %postgresql · postgresql20 нояб. 2019 г.
- CVE-2015-024440В плане
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erro
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %postgresql · postgresql27 янв. 2020 г.
- CVE-2022-2172440В плане
Unchecked Class Instantiation when providing Plugin Classes
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %postgresql · postgresql jdbc driver2 февр. 2022 г.
- CVE-2022-2652040В плане
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %postgresql · postgresql jdbc driver10 мар. 2022 г.
- CVE-2019-1021140В плане
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpro
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %postgresql · postgresql29 окт. 2019 г.
- CVE-2018-105839Наблюдать
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.
ВысокаяCVSS 8,8Proof of conceptEPSS 13 %postgresql · postgresql2 мар. 2018 г.
- CVE-2017-754737Наблюдать
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attack
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %postgresql · postgresql16 авг. 2017 г.
- CVE-2015-024137Наблюдать
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow
ВысокаяCVSS 8,8Эксплойта нетEPSS 6 %postgresql · postgresql27 янв. 2020 г.
- CVE-2015-024237Наблюдать
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %postgresql · postgresql27 янв. 2020 г.
- CVE-2015-024337Наблюдать
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %postgresql · postgresql27 янв. 2020 г.
- CVE-2016-306537Наблюдать
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows atta
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %postgresql · postgresql11 апр. 2016 г.
- CVE-2018-111537Наблюдать
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %postgresql · postgresql10 мая 2018 г.
- CVE-2024-1097936Наблюдать
PostgreSQL PL/Perl environment variable changes execute arbitrary code
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %postgresql · postgresql14 нояб. 2024 г.