Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.1
CVE-2021-3935
- EPSS 1.03%
- Veröffentlicht 22.11.2021 16:15:07
- Zuletzt bearbeitet 03.11.2025 20:15:50
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBounc...
8.1
CVE-2015-6817
- EPSS 2.16%
- Veröffentlicht 23.05.2017 04:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
7.5
CVE-2015-4054
- EPSS 4.13%
- Veröffentlicht 23.05.2017 04:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.