PostgreSQL kayıtları
postgresql üreticisine ait 220 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %1,4
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %86,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls20
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor10
- CWE-189 Numeric Errors8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-20 Improper Input Validation7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
220 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2017-7546İstismar yok | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackerspostgresql · postgresql · CWE-287 | Kritik9,8 | — | %61,6 | 16 Ağu 2017 |
55Planlayın | CVE-2019-9193Silahlaştırılmış | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to postgresql · postgresql · CWE-78 | Yüksek7,2 | — | %91,7 | 1 Nis 2019 |
49Planlayın | CVE-2020-25695İstismar yok | A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.postgresql · postgresql · CWE-89 | Yüksek8,8 | — | %46,4 | 15 Kas 2020 |
44Planlayın | CVE-2007-3280Silahlaştırılmış | The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on thepostgresql · postgresql | Kritik9,0 | — | %25,5 | 19 Haz 2007 |
42Planlayın | CVE-2013-1899Silahlaştırılmış | Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to capostgresql · postgresql · CWE-94 | Orta6,5 | — | %54,3 | 4 Nis 2013 |
41Planlayın | CVE-2018-16850İstismar yok | postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...postgresql · postgresql · CWE-89 | Kritik9,8 | — | %5,2 | 13 Kas 2018 |
41Planlayın | CVE-2007-3279İstismar yok | PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the postgresql · postgresql | Kritik10,0 | — | %2,6 | 19 Haz 2007 |
41Planlayın | CVE-2013-1903İstismar yok | PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly ppostgresql · postgresql · CWE-264 | Kritik10,0 | — | %2,2 | 4 Nis 2013 |
41Planlayın | CVE-2013-1902İstismar yok | PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tempostgresql · postgresql | Kritik10,0 | — | %2,2 | 4 Nis 2013 |
41Planlayın | CVE-2002-1399İstismar yok | Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wipostgresql · postgresql | Kritik10,0 | — | %1,8 | 17 Oca 2003 |
40Planlayın | CVE-2022-1552İstismar yok | A flaw was found in PostgreSQL.postgresql · postgresql · CWE-459 | Yüksek8,8 | — | %16,0 | 31 Ağu 2022 |
40Planlayın | CVE-2024-1597İstismar yok | pgjdbc SQL Injection via line comment generationpostgresql · postgresql jdbc driver · CWE-89 | Kritik9,8 | — | %4,8 | 19 Şub 2024 |
40Planlayın | CVE-2015-3166İstismar yok | The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.postgresql · postgresql · CWE-119 | Kritik9,8 | — | %4,6 | 20 Kas 2019 |
40Planlayın | CVE-2015-0244İstismar yok | PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erropostgresql · postgresql · CWE-89 | Kritik9,8 | — | %4,4 | 27 Oca 2020 |
40Planlayın | CVE-2022-21724İstismar yok | Unchecked Class Instantiation when providing Plugin Classespostgresql · postgresql jdbc driver · CWE-665 | Kritik9,8 | — | %3,1 | 2 Şub 2022 |
40Planlayın | CVE-2022-26520İstismar yok | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary postgresql · postgresql jdbc driver | Kritik9,8 | — | %3,0 | 10 Mar 2022 |
40Planlayın | CVE-2019-10211İstismar yok | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpropostgresql · postgresql · CWE-94 | Kritik9,8 | — | %1,8 | 29 Eki 2019 |
39İzleyin | CVE-2018-1058Kavram kanıtı | A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.postgresql · postgresql · CWE-20 | Yüksek8,8 | — | %13,1 | 2 Mar 2018 |
37İzleyin | CVE-2017-7547İstismar yok | PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackpostgresql · postgresql · CWE-522 | Yüksek8,8 | — | %5,6 | 16 Ağu 2017 |
37İzleyin | CVE-2015-0241İstismar yok | The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allowpostgresql · postgresql · CWE-120 | Yüksek8,8 | — | %5,5 | 27 Oca 2020 |
37İzleyin | CVE-2015-0242İstismar yok | Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9postgresql · postgresql · CWE-787 | Yüksek8,8 | — | %5,1 | 27 Oca 2020 |
37İzleyin | CVE-2015-0243İstismar yok | Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, andpostgresql · postgresql · CWE-120 | Yüksek8,8 | — | %5,1 | 27 Oca 2020 |
37İzleyin | CVE-2016-3065İstismar yok | The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attapostgresql · postgresql · CWE-264 | Kritik9,1 | — | %4,1 | 11 Nis 2016 |
37İzleyin | CVE-2018-1115İstismar yok | postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow postgresql · postgresql · CWE-732 | Kritik9,1 | — | %3,9 | 10 May 2018 |
36İzleyin | CVE-2024-10979İstismar yok | PostgreSQL PL/Perl environment variable changes execute arbitrary codepostgresql · postgresql · CWE-15 | Yüksek8,8 | — | %4,4 | 14 Kas 2024 |
- CVE-2017-754657Planlayın
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers
KritikCVSS 9,8İstismar yokEPSS %62postgresql · postgresql16 Ağu 2017
- CVE-2019-919355Planlayın
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to
YüksekCVSS 7,2SilahlaştırılmışEPSS %92postgresql · postgresql1 Nis 2019
- CVE-2020-2569549Planlayın
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
YüksekCVSS 8,8İstismar yokEPSS %46postgresql · postgresql15 Kas 2020
- CVE-2007-328044Planlayın
The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the
KritikCVSS 9,0SilahlaştırılmışEPSS %25postgresql · postgresql19 Haz 2007
- CVE-2013-189942Planlayın
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to ca
OrtaCVSS 6,5SilahlaştırılmışEPSS %54postgresql · postgresql4 Nis 2013
- CVE-2018-1685041Planlayın
postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ...
KritikCVSS 9,8İstismar yokEPSS %5postgresql · postgresql13 Kas 2018
- CVE-2007-327941Planlayın
PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the
KritikCVSS 10,0İstismar yokEPSS %3postgresql · postgresql19 Haz 2007
- CVE-2013-190341Planlayın
PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly p
KritikCVSS 10,0İstismar yokEPSS %2postgresql · postgresql4 Nis 2013
- CVE-2013-190241Planlayın
PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure tem
KritikCVSS 10,0İstismar yokEPSS %2postgresql · postgresql4 Nis 2013
- CVE-2002-139941Planlayın
Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, wi
KritikCVSS 10,0İstismar yokEPSS %2postgresql · postgresql17 Oca 2003
- CVE-2022-155240Planlayın
A flaw was found in PostgreSQL.
YüksekCVSS 8,8İstismar yokEPSS %16postgresql · postgresql31 Ağu 2022
- CVE-2024-159740Planlayın
pgjdbc SQL Injection via line comment generation
KritikCVSS 9,8İstismar yokEPSS %5postgresql · postgresql jdbc driver19 Şub 2024
- CVE-2015-316640Planlayın
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.
KritikCVSS 9,8İstismar yokEPSS %5postgresql · postgresql20 Kas 2019
- CVE-2015-024440Planlayın
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle erro
KritikCVSS 9,8İstismar yokEPSS %4postgresql · postgresql27 Oca 2020
- CVE-2022-2172440Planlayın
Unchecked Class Instantiation when providing Plugin Classes
KritikCVSS 9,8İstismar yokEPSS %3postgresql · postgresql jdbc driver2 Şub 2022
- CVE-2022-2652040Planlayın
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary
KritikCVSS 9,8İstismar yokEPSS %3postgresql · postgresql jdbc driver10 Mar 2022
- CVE-2019-1021140Planlayın
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unpro
KritikCVSS 9,8İstismar yokEPSS %2postgresql · postgresql29 Eki 2019
- CVE-2018-105839İzleyin
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.
YüksekCVSS 8,8Kavram kanıtıEPSS %13postgresql · postgresql2 Mar 2018
- CVE-2017-754737İzleyin
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attack
YüksekCVSS 8,8İstismar yokEPSS %6postgresql · postgresql16 Ağu 2017
- CVE-2015-024137İzleyin
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow
YüksekCVSS 8,8İstismar yokEPSS %6postgresql · postgresql27 Oca 2020
- CVE-2015-024237İzleyin
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9
YüksekCVSS 8,8İstismar yokEPSS %5postgresql · postgresql27 Oca 2020
- CVE-2015-024337İzleyin
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and
YüksekCVSS 8,8İstismar yokEPSS %5postgresql · postgresql27 Oca 2020
- CVE-2016-306537İzleyin
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows atta
KritikCVSS 9,1İstismar yokEPSS %4postgresql · postgresql11 Nis 2016
- CVE-2018-111537İzleyin
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow
KritikCVSS 9,1İstismar yokEPSS %4postgresql · postgresql10 May 2018
- CVE-2024-1097936İzleyin
PostgreSQL PL/Perl environment variable changes execute arbitrary code
YüksekCVSS 8,8İstismar yokEPSS %4postgresql · postgresql14 Kas 2024