Vulnerability index

Browse CVEs

144 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PostgreSQL CRITICAL 9.8
CVE-2019-10211

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…

Fix: 9.4.24 / 9.5.19+
Fix from $2,300 2019-10-29
PostgreSQL HIGH 8.8
CVE-2019-10208

A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 wh…

Fix: 9.4.24 / 9.5.19+
Fix from $1,950 2019-10-29
PostgreSQL HIGH 7.0
CVE-2019-10210

Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporar…

Fix: 9.4.24 / 9.5.19+
Fix from $1,950 2019-10-29
PostgreSQL MEDIUM 6.5
CVE-2019-10129

A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbi…

Fix: 11.3+
Fix from $1,600 2019-07-30
PostgreSQL HIGH 8.8
CVE-2019-10164

PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overfl…

Fix: 10.9 / 11.4+
Fix from $1,950 2019-06-26
PostgreSQL HIGH 7.2
CVE-2019-9193EPSS 92%

In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute a…

Fix: after 11.2
Fix from $1,950 2019-04-01
PostgreSQL CRITICAL 9.8
CVE-2018-16850EPSS 5%

postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpo…

Fix: 10.6 / 11.1+
Fix from $2,300 2018-11-13
Postgresql Jdbc Driver HIGH 8.1
CVE-2018-10936

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name v…

Fix: 42.2.5+
Fix from $1,950 2018-08-30
PostgreSQL HIGH 8.1
CVE-2016-7048

The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary …

Fix: 9.1.24 / 9.2.19+
Fix from $1,950 2018-08-20
PostgreSQL CRITICAL 9.1
CVE-2018-1115

postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same …

Fix: 9.6.9 / 10.4+
Fix from $2,300 2018-05-10
PostgreSQL HIGH 8.8
CVE-2018-1058EPSS 13%

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use th…

Fix: 9.3.22 / 9.4.17+
Fix from $1,950 2018-03-02
PostgreSQL HIGH 7.0
CVE-2017-14798

A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

Fix: 9.4-0.5.3.1+
Fix from $1,950 2018-03-01
PostgreSQL HIGH 7.0
CVE-2018-1053

In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in curr…

Fix: 9.3.21 / 9.4.16+
Fix from $1,950 2018-02-09
PostgreSQL MEDIUM 6.5
CVE-2018-1052

Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary …

Patch available
Fix from $1,600 2018-02-09
PostgreSQL MEDIUM 6.7
CVE-2017-12172

PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a …

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL MEDIUM 6.5
CVE-2017-15099EPSS 6%

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that th…

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL HIGH 8.1
CVE-2017-15098

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9…

Mitigation only
Fix from $1,950 2017-11-22
PostgreSQL MEDIUM 5.5
CVE-2017-8806

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 f…

Mitigation only
Fix from $1,600 2017-11-13
PostgreSQL CRITICAL 9.8
CVE-2017-7546EPSS 62%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain …

Mitigation only
Fix from $2,300 2017-08-16
PostgreSQL HIGH 8.8
CVE-2017-7547EPSS 6%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re…

Mitigation only
Fix from $1,950 2017-08-16
PostgreSQL HIGH 7.5
CVE-2017-7548

PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on…

Fix: 9.4.13 / 9.5.8+
Fix from $1,950 2017-08-16
PostgreSQL HIGH 7.5
CVE-2016-0768

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

Fix: after 9.0
Fix from $1,950 2017-06-06
PostgreSQL HIGH 7.5
CVE-2017-7484

It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, an…

Fix: after 9.2.20
Fix from $1,950 2017-05-12
PostgreSQL HIGH 7.5
CVE-2017-7486EPSS 6%

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having…

Mitigation only
Fix from $1,950 2017-05-12
PostgreSQL MEDIUM 5.9
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment va…

Mitigation only
Fix from $1,600 2017-05-12
PostgreSQL CRITICAL 9.1
CVE-2016-3065

The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to …

Patch available
Fix from $2,300 2016-04-11
PostgreSQL HIGH 7.5
CVE-2016-2193

PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended a…

Patch available
Fix from $1,950 2016-04-11
PostgreSQL HIGH 7.5
CVE-2016-0773EPSS 7%

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a den…

Fix: after 9.1.19
Fix from $1,950 2016-02-17
PostgreSQL HIGH 8.8
CVE-2016-0766

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to u…

Fix: 9.1.20 / 9.2.15+
Fix from $1,950 2016-02-17
PostgreSQL MEDIUM 6.4
CVE-2015-5289EPSS 5%

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a deni…

Fix: 9.3.10 / 9.4.5+
Fix from $1,600 2015-10-26