|
11
|
3.7
-
|
LOW
Network
|
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to…
|
NVD-CWE-noinfo
|
CVE-2022-41862
|
cpe:2.3:a:postgresql:postgresql:*:*
|
15.0 14.0 13.0 12.0
|
|
|
15.2 14.7 13.10 12.14
|
2025-03-8 01:15
2023-03-4
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
8.8
-
|
HIGH
Network
|
A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRES…
|
-
|
CVE-2022-1552
|
cpe:2.3:a:postgresql:postgresql:*:*
|
14.0 13.0 12.0 11.0 10.0
|
|
|
14.3 13.7 12.11 11.16 10.21
|
2024-11-21 15:40
2022-09-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
5.9
-
|
MEDIUM
Network
|
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to us…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-43767
|
cpe:2.3:a:postgresql:postgresql:14.0:* cpe:2.3:a:postgresql:postgresql:*:*
|
10.0 11.0 12.0 13.0 9.6.0
|
|
|
10.19 11.14 12.9 13.5 9.6.24
|
2024-11-21 15:29
2022-08-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
8.0
-
|
HIGH
Network
|
A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update a…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2022-2625
|
cpe:2.3:a:postgresql:postgresql:15:beta2 cpe:2.3:a:postgresql:postgresql:15:beta1 cpe:2.3:a:postgresql:postgresql…
|
10.0 11.0 12.0 13.0 14.0
|
|
|
10.22 11.17 12.12 13.8 14.5
|
2024-11-21 16:01
2022-08-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
8.1
5.1
|
HIGH
Network
|
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection …
|
-
|
CVE-2021-23214
|
cpe:2.3:a:postgresql:postgresql:14.0:* cpe:2.3:a:postgresql:postgresql:*:*
|
10.0 11.0 12.0 13.0
|
|
|
10.19 11.14 12.9 13.5 9.6.24
|
2024-11-21 14:51
2022-03-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
5.9
4.3
|
MEDIUM
Network
|
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.
|
-
|
CVE-2021-23222
|
cpe:2.3:a:postgresql:postgresql:14.0:* cpe:2.3:a:postgresql:postgresql:*:*
|
9.6 10.0 11.0 12.0 13.0
|
|
|
9.6.24 10.19 11.14 12.9 13.5
|
2024-11-21 14:51
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
6.5
4.0
|
MEDIUM
Network
|
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The …
|
-
|
CVE-2021-3677
|
cpe:2.3:a:postgresql:postgresql:*:*
|
13.0 12.0 11.0
|
|
|
13.4 12.8 11.13
|
2024-11-21 15:22
2022-03-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
6.5
4.0
|
MEDIUM
Network
|
A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highe…
|
NVD-CWE-noinfo
|
CVE-2021-32028
|
cpe:2.3:a:postgresql:postgresql:*:*
|
13.0 12.0 10.0 11.0 9.6.0
|
|
|
13.3 12.7 10.17 11.12 9.6.22
|
2024-11-21 15:06
2021-10-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
6.5
4.0
|
MEDIUM
Network
|
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from t…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-32029
|
cpe:2.3:a:postgresql:postgresql:*:*
|
13.0 12.0 11.0
|
|
|
13.3 12.7 11.12
|
2024-11-21 15:06
2021-10-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
8.8
6.5
|
HIGH
Network
|
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated da…
|
-
|
CVE-2021-32027
|
cpe:2.3:a:postgresql:postgresql:*:*
|
13.0 12.0 10.0 11.0 9.6.0
|
|
|
13.3 12.7 10.17 11.12 9.6.22
|
2024-11-21 15:06
2021-06-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|