CVE-2021-32029
- EPSS 0.24%
- Veröffentlicht 08.10.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:06:44
A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data confidentiality.
CVE-2021-32027
- EPSS 0.49%
- Veröffentlicht 01.06.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:06:44
A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area o...
CVE-2021-3393
- EPSS 0.09%
- Veröffentlicht 01.04.2021 14:15:13
- Zuletzt bearbeitet 21.11.2024 06:21:24
An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under some circumstances, might disclo...
CVE-2019-10128
- EPSS 0.07%
- Veröffentlicht 19.03.2021 20:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:28
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited A...
CVE-2019-10127
- EPSS 0.09%
- Veröffentlicht 19.03.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:28
A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps the inherited ACL. In...
CVE-2021-20229
- EPSS 0.07%
- Veröffentlicht 23.02.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:10
A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
CVE-2020-25696
- EPSS 0.2%
- Veröffentlicht 23.11.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:30
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attac...
CVE-2020-25694
- EPSS 0.12%
- Veröffentlicht 16.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If a client application that creates additional database connections only reuses the basic connection parameters while drop...
CVE-2020-25695
- EPSS 23.34%
- Veröffentlicht 16.11.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:18:29
A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions un...
CVE-2020-10733
- EPSS 0.25%
- Veröffentlicht 16.09.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:57
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended execut...