Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

PostgreSQL HIGH 7.2
CVE-2026-6471

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating…

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 8.8
CVE-2026-14677

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write …

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 8.8
CVE-2026-14680

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the data…

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 8.2
CVE-2026-14679

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack c…

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL HIGH 8.8
CVE-2026-14676

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the data…

No fix yet
Fix from $4,900 2026-08-13
PostgreSQL MEDIUM 6.7
CVE-2017-12172

PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a …

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL MEDIUM 6.5
CVE-2017-15099EPSS 6%

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that th…

Mitigation only
Fix from $1,600 2017-11-22
PostgreSQL HIGH 8.1
CVE-2017-15098

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9…

Mitigation only
Fix from $1,950 2017-11-22
PostgreSQL MEDIUM 5.5
CVE-2017-8806

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 f…

Mitigation only
Fix from $1,600 2017-11-13
PostgreSQL CRITICAL 9.8
CVE-2017-7546EPSS 62%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain …

Mitigation only
Fix from $2,300 2017-08-16
PostgreSQL HIGH 8.8
CVE-2017-7547EPSS 6%

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to re…

Mitigation only
Fix from $1,950 2017-08-16
PostgreSQL HIGH 7.5
CVE-2017-7486EPSS 6%

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having…

Mitigation only
Fix from $1,950 2017-05-12
PostgreSQL MEDIUM 5.9
CVE-2017-7485

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment va…

Mitigation only
Fix from $1,600 2017-05-12
PostgreSQL HIGH 10.0
CVE-2013-1902

PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary fi…

Mitigation only
Fix from $1,950 2013-04-04
PostgreSQL HIGH 10.0
CVE-2013-1903

PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…

Mitigation only
Fix from $1,950 2013-04-04
PostgreSQL HIGH 8.5
CVE-2013-1900

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random …

Mitigation only
Fix from $1,950 2013-04-04
PostgreSQL MEDIUM 6.5
CVE-2013-1899EPSS 54%

Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2013-04-04
PostgreSQL MEDIUM 6.8
CVE-2013-0255

PostgreSQL 9.2.x before 9.2.3, 9.1.x before 9.1.8, 9.0.x before 9.0.12, 8.4.x before 8.4.16, and 8.3.x before 8.3.23 does not properly declare the en…

Mitigation only
Fix from $1,600 2013-02-13
PostgreSQL HIGH 7.5
CVE-2012-1618

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled,…

Mitigation only
Fix from $1,950 2012-10-06
PostgreSQL MEDIUM 6.8
CVE-2012-0868

CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows use…

Mitigation only
Fix from $1,600 2012-07-18
PostgreSQL MEDIUM 6.5
CVE-2012-0866

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute…

Mitigation only
Fix from $1,600 2012-07-18
PostgreSQL MEDIUM 6.5
CVE-2010-4015

Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before …

Mitigation only
Fix from $1,600 2011-02-02
PostgreSQL MEDIUM 5.5
CVE-2010-1975

PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly chec…

Mitigation only
Fix from $1,600 2010-05-19
PostgreSQL MEDIUM 6.5
CVE-2009-3230

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7…

Mitigation only
Fix from $1,600 2009-09-17
PostgreSQL HIGH 10.0
CVE-2007-3279

PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do…

Mitigation only
Fix from $1,950 2007-06-19
PostgreSQL HIGH 9.0
CVE-2007-3280EPSS 25%

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C progra…

Mitigation only
Fix from $1,950 2007-06-19
PostgreSQL MEDIUM 6.6
CVE-2007-0556

The query planner in PostgreSQL before 8.0.11, 8.1 before 8.1.7, and 8.2 before 8.2.2 does not verify that a table is compatible with a "previously m…

Mitigation only
Fix from $1,600 2007-02-06
PostgreSQL HIGH 10.0
CVE-2002-1399

Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow…

Mitigation only
Fix from $1,950 2003-01-17
PostgreSQL HIGH 7.5
CVE-2002-1397

Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitr…

Mitigation only
Fix from $1,950 2003-01-17
PostgreSQL HIGH 7.5
CVE-2002-1400

Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to gen…

Mitigation only
Fix from $1,950 2003-01-17