Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 154 CRITICAL 7 HIGH 63 MEDIUM 77 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • オープンソース
  • PostgreSQL Licence
  • 商用ライセンス有り

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
141 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 2 2 0
142 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 6 4 1
143 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 8 5 1
144 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 12 10 1
145 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 15 11 1
146 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 19 12 1
147 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 21 9 0
148 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 39 37 0
149 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 31 48 3
150 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 31 38 4
151 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 21 20 2
152 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 21 22 1
153 PostgreSQL - - 4 17 14 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
141 -
5.0
MEDIUM Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). NVD-CWE-Other
CVE-2004-0547 cpe:2.3:a:postgresql:postgresql:7.2.1:* 2017-07-11 10:30
2004-08-6
Show GitHub Exploit DB Packet Storm
142 -
7.5
HIGH Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. NVD-CWE-Other
CVE-2003-0901 cpe:2.3:a:postgresql:postgresql:7.3:*
cpe:2.3:a:postgresql:postgresql:7.3.3:*
cpe:2.3:a:postgresql:postgresql:7.3…
2008-09-6 05:35
2003-11-3
Show GitHub Exploit DB Packet Storm
143 -
7.5
HIGH Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly t… NVD-CWE-Other
CVE-2002-1397 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.1:*
cpe:2.3:a:postgresql:postgresql:7.1.3…
2017-07-11 10:29
2003-01-17
Show GitHub Exploit DB Packet Storm
144 -
4.6
MEDIUM Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handli… NVD-CWE-Other
CVE-2002-1398 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
145 -
10.0
HIGH Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which … NVD-CWE-Other
CVE-2002-1399 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
146 -
7.5
HIGH Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. NVD-CWE-Other
CVE-2002-1400 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
147 -
6.5
MEDIUM Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and poss… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2002-1401 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.3:*
cpe:2.3:a:postgresql:postgresql:7.2…
2008-09-10 13:00
2003-01-17
Show GitHub Exploit DB Packet Storm
148 -
4.6
MEDIUM Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. NVD-CWE-Other
CVE-2002-1402 cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
149 7.5
5.0
HIGH
Network
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2002-1657 cpe:2.3:a:postgresql:postgresql:7.3.19:* 2024-02-9 12:06
2002-12-31
Show GitHub Exploit DB Packet Storm
150 -
7.2
HIGH PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command. NVD-CWE-Other
CVE-2002-1642 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.2:*
cpe:2.3:a:postgresql:postgresql:7.2…
2017-07-11 10:29
2002-10-3
Show GitHub Exploit DB Packet Storm