Postgresql

Postgresql

168 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 30.23%
  • Veröffentlicht 22.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full re...

  • EPSS 0.77%
  • Veröffentlicht 22.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server me...

  • EPSS 0.16%
  • Veröffentlicht 13.11.2017 09:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, w...

  • EPSS 33.2%
  • Veröffentlicht 16.08.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

  • EPSS 0.93%
  • Veröffentlicht 16.08.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having ...

  • EPSS 1.06%
  • Veröffentlicht 16.08.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.

  • EPSS 0.24%
  • Veröffentlicht 06.06.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

  • EPSS 1.44%
  • Veröffentlicht 12.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, po...

  • EPSS 1.32%
  • Veröffentlicht 12.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Midd...

  • EPSS 4.12%
  • Veröffentlicht 12.05.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.