Vulnerability index

Browse CVEs

144 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-10211 Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di… PostgreSQL 9.4.24 / 9.5.19+ Fix from $2,3002019-10-29 HIGH 8.8 CVE-2019-10208 A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 wh… PostgreSQL 9.4.24 / 9.5.19+ Fix from $1,9502019-10-29 HIGH 7.0 CVE-2019-10210 Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporar… PostgreSQL 9.4.24 / 9.5.19+ Fix from $1,9502019-10-29 MEDIUM 6.5 CVE-2019-10129 A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned table, an attacker can read arbi… PostgreSQL 11.3+ Fix from $1,6002019-07-30 HIGH 8.8 CVE-2019-10164 PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overfl… PostgreSQL 10.9 / 11.4+ Fix from $1,9502019-06-26 HIGH 7.2 CVE-2019-9193EPSS 92% In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_server_program' group to execute a… PostgreSQL after 11.2 Fix from $1,9502019-04-01 CRITICAL 9.8 CVE-2018-16850EPSS 5% postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpo… PostgreSQL 10.6 / 11.1+ Fix from $2,3002018-11-13 HIGH 8.1 CVE-2018-10936 A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name v… Postgresql Jdbc Driver 42.2.5+ Fix from $1,9502018-08-30 HIGH 8.1 CVE-2016-7048 The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary … PostgreSQL 9.1.24 / 9.2.19+ Fix from $1,9502018-08-20 CRITICAL 9.1 CVE-2018-1115 postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same … PostgreSQL 9.6.9 / 10.4+ Fix from $2,3002018-05-10 HIGH 8.8 CVE-2018-1058EPSS 13% A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use th… PostgreSQL 9.3.22 / 9.4.17+ Fix from $1,9502018-03-02 HIGH 7.0 CVE-2017-14798 A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root. PostgreSQL 9.4-0.5.3.1+ Fix from $1,9502018-03-01 HIGH 7.0 CVE-2018-1053 In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in curr… PostgreSQL 9.3.21 / 9.4.16+ Fix from $1,9502018-02-09 MEDIUM 6.5 CVE-2018-1052 Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary … PostgreSQL Patch available Fix from $1,6002018-02-09 MEDIUM 6.7 CVE-2017-12172 PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a … PostgreSQL Mitigation only Fix from $1,6002017-11-22 MEDIUM 6.5 CVE-2017-15099EPSS 6% INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that th… PostgreSQL Mitigation only Fix from $1,6002017-11-22 HIGH 8.1 CVE-2017-15098 Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9… PostgreSQL Mitigation only Fix from $1,9502017-11-22 MEDIUM 5.5 CVE-2017-8806 The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 f… PostgreSQL Mitigation only Fix from $1,6002017-11-13 CRITICAL 9.8 CVE-2017-7546EPSS 62% PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain … PostgreSQL Mitigation only Fix from $2,3002017-08-16 HIGH 8.8 CVE-2017-7547EPSS 6% PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re… PostgreSQL Mitigation only Fix from $1,9502017-08-16 HIGH 7.5 CVE-2017-7548 PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on… PostgreSQL 9.4.13 / 9.5.8+ Fix from $1,9502017-08-16 HIGH 7.5 CVE-2016-0768 PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. PostgreSQL after 9.0 Fix from $1,9502017-06-06 HIGH 7.5 CVE-2017-7484 It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, an… PostgreSQL after 9.2.20 Fix from $1,9502017-05-12 HIGH 7.5 CVE-2017-7486EPSS 6% PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having… PostgreSQL Mitigation only Fix from $1,9502017-05-12 MEDIUM 5.9 CVE-2017-7485 In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment va… PostgreSQL Mitigation only Fix from $1,6002017-05-12 CRITICAL 9.1 CVE-2016-3065 The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to … PostgreSQL Patch available Fix from $2,3002016-04-11 HIGH 7.5 CVE-2016-2193 PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended a… PostgreSQL Patch available Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-0773EPSS 7% PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a den… PostgreSQL after 9.1.19 Fix from $1,9502016-02-17 HIGH 8.8 CVE-2016-0766 PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to u… PostgreSQL 9.1.20 / 9.2.15+ Fix from $1,9502016-02-17 MEDIUM 6.4 CVE-2015-5289EPSS 5% Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a deni… PostgreSQL 9.3.10 / 9.4.5+ Fix from $1,6002015-10-26