CRITICAL9.8CVE-2018-16850postgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... from 0, < 11.1-r0
from 0, < 9.6.4-r0
CRITICAL9.1postgresql before versions 10.4, 9.6.9 is vulnerable in the adminpack extension, the pg_catalog.pg_logfile_rotate() function doesn't follow…
from 0, < 10.4-r0
HIGH8.8PostgreSQL refint allows stack buffer overflow and SQL injection
from 0, < 15.18-r0
HIGH8.8PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
from 0, < 15.18-r0
HIGH8.8PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
from 0, < 15.18-r0
HIGH8.8PostgreSQL server undersizes allocations, via integer wraparound
from 0, < 15.18-r0
HIGH8.8PostgreSQL missing validation of multibyte character length executes arbitrary code
from 0, < 15.16-r0
HIGH8.8PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
from 0, < 15.16-r0
HIGH8.8PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
from 0, < 15.16-r0
HIGH8.8PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
from 0, < 15.14-r0
HIGH8.8PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
from 0, < 15.14-r0
HIGH8.8PostgreSQL PL/Perl environment variable changes execute arbitrary code
from 0, < 15.9-r0
HIGH8.8Postgresql: buffer overrun from integer overflow in array modification
from 0, < 15.5-r0
HIGH8.8postgresql-13 - security update
from 0, < 15.4-r0
HIGH8.8postgresql-13 - security update
from 0, < 14.3-r0
HIGH8.8postgresql-11 - security update
from 0, < 13.3-r0
HIGH8.8A flaw was found in PostgreSQL versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24.
from 0, < 12.5-r0
HIGH8.8postgresql-11 - security update
from 0, < 11.5-r0
HIGH8.8PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow.
from 0, < 11.4-r0
HIGH8.8A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users.
from 0, < 10.3-r0
HIGH8.8PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attac…
from 0, < 9.6.4-r0
HIGH8.2PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
from 0, < 15.16-r0
HIGH8.1postgresql-13 - regression update
from 0, < 15.11-r0
HIGH8.1postgresql-13 - security update
from 0, < 14.1-r0
HIGH8.1postgresql-9.6 - security update
from 0, < 12.5-r0
HIGH8.1It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certai…
from 0, < 10.5-r0
HIGH8.1postgresql-9.6 - security update
from 0, < 10.1-r0
HIGH8.0postgresql-15 - security update
from 0, < 15.6-r0
HIGH8.0postgresql-11 - security update
from 0, < 14.5-r0
HIGH7.5PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
from 0, < 15.18-r0
HIGH7.5postgresql-13 - security update
from 0, < 15.8-r0
HIGH7.5A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.…
from 0, < 12.5-r0
HIGH7.5postgresql-9.6 - security update
from 0, < 10.5-r0
HIGH7.5PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no pri…
from 0, < 9.6.4-r0
HIGH7.5postgresql-9.1 - security update
from 0, < 9.6.3-r0
HIGH7.5postgresql-9.4 - security update
from 0, < 9.6.3-r0
HIGH7.3postgresql-9.6 - security update
from 0, < 12.4-r0
HIGH7.2postgresql-13 - security update
from 0, < 15.3-r0
HIGH7.1It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical re…
from 0, < 12.4-r0
HIGH7.0postgresql-9.1 - security update
from 0, < 10.2-r0
MEDIUM6.5PostgreSQL discloses MD5-hashed passwords via covert timing channel
from 0, < 15.18-r0
MEDIUM6.5A flaw was found in postgresql.
from 0, < 13.4-r0
MEDIUM6.5A flaw was found in postgresql.
from 0, < 13.3-r0
MEDIUM6.5A flaw was found in postgresql.
from 0, < 13.3-r0
MEDIUM6.5postgresql-11 - security update
from 0, < 12.2-r0
MEDIUM6.5A vulnerability was found in postgresql versions 11.x prior to 11.3.
from 0, < 11.3-r0
MEDIUM6.5Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read…
from 0, < 10.2-r0
MEDIUM6.5INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table conten…
from 0, < 10.1-r0
MEDIUM5.9PostgreSQL libpq undersizes allocations, via integer wraparound
from 0, < 15.15-r0
MEDIUM5.9postgresql-13 - security update
from 0, < 15.13-r0
MEDIUM5.9A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification…
from 0, < 14.1-r0
MEDIUM5.9In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL envi…
from 0, < 9.6.3-r0
MEDIUM5.4PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
from 0, < 15.18-r0
MEDIUM5.4postgresql-15 - security update
from 0, < 15.9-r0
MEDIUM5.4Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases w…
from 0, < 15.3-r0
MEDIUM4.4Postgresql: role pg_signal_backend can signal certain superuser processes.
from 0, < 15.5-r0
MEDIUM4.3PostgreSQL timeofday() can disclose portions of server memory
from 0, < 15.18-r0
MEDIUM4.3postgresql-17 - security update
from 0, < 15.16-r0
MEDIUM4.3postgresql-11 - security update
from 0, < 15.5-r0
MEDIUM4.3Postgresql: merge fails to enforce update or select row security policies
from 0, < 15.4-r0
MEDIUM4.3An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11.
from 0, < 13.2-r0
MEDIUM4.3A flaw was found in PostgreSQL in versions before 13.2.
from 0, < 13.2-r0
MEDIUM4.3postgresql-9.6 - security update
from 0, < 11.3-r0
MEDIUM4.2PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID
from 0, < 15.9-r0
LOW3.7PostgreSQL libpq retains an error message from man-in-the-middle
from 0, < 15.9-r0
LOW3.7In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption.
from 0, < 15.2-r0
LOW3.1postgresql-13 - security update
from 0, < 15.15-r0
LOW3.1postgresql-13 - security update
from 0, < 15.14-r0
LOW2.2Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
from 0, < 11.5-r0