CVE-2016-3065
- EPSS 1.12%
- Published 11.04.2016 15:59:06
- Last modified 12.04.2025 10:46:40
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or ca...
CVE-2016-2193
- EPSS 1.53%
- Published 11.04.2016 15:59:04
- Last modified 12.04.2025 10:46:40
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
CVE-2016-0773
- EPSS 6.95%
- Published 17.02.2016 15:59:02
- Last modified 12.04.2025 10:46:40
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a ...
- EPSS 0.97%
- Published 17.02.2016 15:59:01
- Last modified 12.04.2025 10:46:40
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privilege...
CVE-2015-5289
- EPSS 11.24%
- Published 26.10.2015 14:59:02
- Last modified 12.04.2025 10:46:40
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (...
CVE-2015-5288
- EPSS 5.22%
- Published 26.10.2015 14:59:01
- Last modified 12.04.2025 10:46:40
The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via...
CVE-2015-3165
- EPSS 8.53%
- Published 28.05.2015 14:59:06
- Last modified 12.04.2025 10:46:40
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the auth...
CVE-2014-2669
- EPSS 0.94%
- Published 31.03.2014 14:58:19
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact via vectors related to the (1) hst...
CVE-2014-0061
- EPSS 1.57%
- Published 31.03.2014 14:58:15
- Last modified 12.04.2025 10:46:40
The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privileges via a function that is (1...
CVE-2014-0062
- EPSS 0.66%
- Published 31.03.2014 14:58:15
- Last modified 12.04.2025 10:46:40
Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticated users to create an unauthori...