CVE-2020-14349
- EPSS 0.69%
- Veröffentlicht 24.08.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:03:04
It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication. An authenticated attacker could use this flaw in an attack similar to CVE-2018-1058, in order to exe...
CVE-2020-14350
- EPSS 0.03%
- Veröffentlicht 24.08.2020 13:15:10
- Zuletzt bearbeitet 21.11.2024 05:03:04
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the insta...
CVE-2020-1720
- EPSS 0.15%
- Veröffentlicht 17.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:14
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et...
CVE-2014-8161
- EPSS 0.58%
- Veröffentlicht 27.01.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:18:41
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
CVE-2015-0241
- EPSS 3.38%
- Veröffentlicht 27.01.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:22:38
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1)...
CVE-2015-0242
- EPSS 3.27%
- Veröffentlicht 27.01.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:22:38
Stack-based buffer overflow in the *printf function implementations in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1, when running on a Windows system, allows remote authenticated users...
CVE-2015-0243
- EPSS 3.61%
- Veröffentlicht 27.01.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:22:38
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute...
CVE-2015-0244
- EPSS 1.08%
- Veröffentlicht 27.01.2020 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:22:38
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafte...
CVE-2015-3166
- EPSS 2.91%
- Veröffentlicht 20.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 02:28:48
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have ...
CVE-2015-3167
- EPSS 2.51%
- Veröffentlicht 20.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 02:28:48
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via...