Vulnerabilities
Vulnerable Software
Postgresql:  >> Postgresql  >> 1.02  Security Vulnerabilities
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
CVSS Score
7.5
EPSS Score
0.018
Published
2019-11-20
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
CVSS Score
6.7
EPSS Score
0.003
Published
2019-10-29
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
CVSS Score
7.8
EPSS Score
0.012
Published
2019-10-29
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
CVSS Score
8.1
EPSS Score
0.121
Published
2018-08-20
postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow the same ACLs than pg_rorate_logfile. If the adminpack is added to a database, an attacker able to connect to it could exploit this to force log rotation.
CVSS Score
4.2
EPSS Score
0.006
Published
2018-05-10
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
CVSS Score
7.3
EPSS Score
0.008
Published
2018-03-01
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
CVSS Score
7.5
EPSS Score
0.002
Published
2017-06-06
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.
CVSS Score
7.5
EPSS Score
0.014
Published
2017-05-12
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quote), (2) \ (backslash), (3) carriage return, or (4) newline character in a (a) database or (b) role name that is mishandled during an administrative operation.
CVSS Score
7.1
EPSS Score
0.017
Published
2016-12-09
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL pointer dereference and server crash), obtain sensitive memory information, or possibly execute arbitrary code via (1) a CASE expression within the test value subexpression of another CASE or (2) inlining of an SQL function that implements the equality operator used for a CASE expression involving values of different types.
CVSS Score
8.3
EPSS Score
0.034
Published
2016-12-09


Contact Us

Shodan ® - All rights reserved