Vulnerability index

Browse CVEs

144 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Postgresql Jdbc Driver MEDIUM 5.5
CVE-2022-41946

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)`…

Fix: 42.2.27 / 42.3.8+
Fix from $1,600 2022-11-23
PostgreSQL HIGH 8.8
CVE-2022-1552EPSS 12%

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's obje…

Fix: 10.21 / 11.16+
Fix from $1,950 2022-08-31
PostgreSQL MEDIUM 5.9
CVE-2021-43767

Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authe…

Fix: 9.6.24 / 10.19+
Fix from $1,600 2022-08-25
PostgreSQL HIGH 8.0
CVE-2022-2625

A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure …

Fix: 10.22 / 11.17+
Fix from $1,950 2022-08-18
Postgresql Jdbc Driver HIGH 8.0
CVE-2022-31197

PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Th…

Fix: 42.2.26 / 42.3.7+
Fix from $1,950 2022-08-03
Postgresql Jdbc Driver CRITICAL 9.8
CVE-2022-26520

In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files thr…

Fix: 42.3.3+
Fix from $2,300 2022-03-10
PostgreSQL HIGH 8.1
CVE-2021-23214

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker c…

Fix: 9.6.24 / 10.19+
Fix from $1,950 2022-03-04
PostgreSQL MEDIUM 6.5
CVE-2021-3677

A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated da…

Fix: 11.13 / 12.8+
Fix from $1,600 2022-03-02
PostgreSQL MEDIUM 5.9
CVE-2021-23222

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryp…

Fix: 9.6.24 / 10.19+
Fix from $1,600 2022-03-02
Postgresql Jdbc Driver CRITICAL 9.8
CVE-2022-21724

pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The…

Fix: 2.7.2 / 42.2.25+
Fix from $2,300 2022-02-02
PostgreSQL MEDIUM 6.5
CVE-2021-32028

A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user coul…

Fix: 9.6.22 / 10.17+
Fix from $1,600 2021-10-11
PostgreSQL MEDIUM 6.5
CVE-2021-32029

A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary…

Fix: 11.12 / 12.7+
Fix from $1,600 2021-10-08
PostgreSQL HIGH 8.8
CVE-2021-32027

A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array …

Fix: 9.6.22 / 10.17+
Fix from $1,950 2021-06-01
PostgreSQL HIGH 7.8
CVE-2019-10128

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down th…

Fix: 9.4.22 / 9.5.17+
Fix from $1,950 2021-03-19
PostgreSQL HIGH 8.8
CVE-2019-10127

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL …

Fix: 9.4.22 / 9.5.17+
Fix from $1,950 2021-03-19
PostgreSQL HIGH 7.5
CVE-2020-25696

A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and b…

Fix: 9.5.24 / 9.6.20+
Fix from $1,950 2020-11-23
PostgreSQL HIGH 8.8
CVE-2020-25695EPSS 46%

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having per…

Fix: 9.5.24 / 9.6.20+
Fix from $1,950 2020-11-16
PostgreSQL HIGH 8.1
CVE-2020-25694

A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client applicatio…

Fix: 9.5.24 / 9.6.20+
Fix from $1,950 2020-11-16
PostgreSQL HIGH 7.3
CVE-2020-10733

The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the director…

Fix: 9.5.22 / 9.6.18+
Fix from $1,950 2020-09-16
PostgreSQL HIGH 7.3
CVE-2020-14350

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges coul…

Fix: 9.5.23 / 9.6.19+
Fix from $1,950 2020-08-24
PostgreSQL HIGH 7.1
CVE-2020-14349

It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication.…

Fix: 10.14 / 11.9+
Fix from $1,950 2020-08-24
Postgresql Jdbc Driver HIGH 7.7
CVE-2020-13692

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

Fix: 42.2.13+
Fix from $1,950 2020-06-04
PostgreSQL MEDIUM 6.5
CVE-2020-1720

A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker…

Fix: 9.6.17 / 10.12+
Fix from $1,600 2020-03-17
PostgreSQL CRITICAL 9.8
CVE-2015-0244

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while …

Fix: 9.0.19 / 9.1.15+
Fix from $2,300 2020-01-27
PostgreSQL HIGH 8.8
CVE-2015-0241EPSS 6%

The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote …

Fix: 9.0.19 / 9.1.15+
Fix from $1,950 2020-01-27
PostgreSQL HIGH 8.8
CVE-2015-0242EPSS 5%

Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x befo…

Fix: 9.0.19 / 9.1.15+
Fix from $1,950 2020-01-27
PostgreSQL HIGH 8.8
CVE-2015-0243EPSS 5%

Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x be…

Fix: 9.0.19 / 9.1.15+
Fix from $1,950 2020-01-27
PostgreSQL CRITICAL 9.8
CVE-2015-3166

The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does no…

Fix: 9.0.20 / 9.1.16+
Fix from $2,300 2019-11-20
PostgreSQL HIGH 7.5
CVE-2015-3167

contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different err…

Fix: 9.0.20 / 9.1.16+
Fix from $1,950 2019-11-20
Postgresql Common HIGH 7.8
CVE-2019-3466

The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, …

Fix: 210+
Fix from $1,950 2019-11-20