|
31
|
6.5
3.5
|
MEDIUM
Network
|
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to …
|
CWE-862
Missing Authorization
|
CVE-2020-1720
|
cpe:2.3:a:postgresql:postgresql:*:*
|
12.0 11.0 10.0 9.6
|
|
|
12.2 11.7 10.12 9.6.17
|
2024-11-21 14:11
2020-03-18
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
9.8
7.5
|
CRITICAL
Network
|
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote at…
|
CWE-89
SQL Injection
|
CVE-2015-0244
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.1.0 9.2.0 9.3.0 9.4.0
|
|
|
9.0.19 9.1.15 9.2.10 9.3.6 9.4.1
|
2024-11-21 11:22
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
8.8
6.5
|
HIGH
Network
|
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cau…
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-0243
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.1.0 9.2.0 9.3.0 9.4.0
|
|
|
9.0.19 9.1.15 9.2.10 9.3.6 9.4.1
|
2024-11-21 11:22
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
8.8
6.5
|
HIGH
Network
|
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on …
|
CWE-787
Out-of-bounds Write
|
CVE-2015-0242
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.1.0 9.2.0 9.3.0 9.4.0
|
|
|
9.0.19 9.1.15 9.2.10 9.3.6 9.4.1
|
2024-11-21 11:22
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
8.8
6.5
|
HIGH
Network
|
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (…
|
CWE-120
Classic Buffer Overflow
|
CVE-2015-0241
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.1.0 9.2.0 9.3.0 9.4.0
|
|
|
9.0.19 9.1.15 9.2.10 9.3.6 9.4.1
|
2024-11-21 11:22
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
4.3
4.0
|
MEDIUM
Network
|
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constr…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2014-8161
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.1.0 9.2.0 9.3.0 9.4.0
|
|
|
9.0.19 9.1.15 9.2.10 9.3.6 9.4.1
|
2024-11-21 11:18
2020-01-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
7.5
5.0
|
HIGH
Network
|
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which …
|
CWE-200
Information Exposure
|
CVE-2015-3167
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.4 9.3 9.2 9.1
|
|
|
9.4.2 9.3.7 9.2.11 9.1.16 9.0.20
|
2024-11-21 11:28
2019-11-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
9.8
7.5
|
CRITICAL
Network
|
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3166
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.4 9.3 9.2 9.1
|
|
|
9.4.2 9.3.7 9.2.11 9.1.16 9.0.20
|
2024-11-21 11:28
2019-11-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
9.8
7.5
|
CRITICAL
Network
|
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
|
NVD-CWE-noinfo
|
CVE-2019-10211
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.5.0 9.6.0 10.0 11.0
|
|
|
9.4.24 9.5.19 9.6.15 10.10 11.5
|
2024-11-21 13:18
2019-10-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
7.0
1.9
|
HIGH
Local
|
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2019-10210
|
cpe:2.3:a:postgresql:postgresql:*:*
|
9.5.0 9.6.0 10.0 11.0
|
|
|
9.4.24 9.5.19 9.6.15 10.10 11.5
|
2024-11-21 13:18
2019-10-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|