Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postgresql vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2001-1379
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote malicious users to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.
Guiseppe Tanzilli And Matthias Eckermann Mod Auth Pgsql 0.9.5
Guiseppe Tanzilli And Matthias Eckermann Mod Auth Pgsql 0.9.6
668
VMScore
CVE-2001-0201
The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote malicious users to execute arbitrary SQL queries via the deletecontact.php program.
Umut Gokbayrak Postaci 1.1.3
Umut Gokbayrak Postaci 1.1.2
655
VMScore
CVE-2010-0442
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstra...
Postgresql Postgresql
1 EDB exploit
645
VMScore
CVE-2011-2202
The rfc1867_post_handler function in main/rfc1867.c in PHP prior to 5.3.7 does not properly restrict filenames in multipart/form-data POST requests, which allows remote malicious users to conduct absolute path traversal attacks, and possibly create or overwrite arbitrary files, v...
Php Php 5.3.0
Php Php 4.0.4
Php Php 4.0.5
Php Php 4.0
Php Php 4.1.0
Php Php 4.2.2
Php Php 4.2.3
Php Php 4.3.3
Php Php 4.3.4
Php Php 4.4.1
Php Php 4.4.2
Php Php 3.0.11
Php Php 3.0.10
Php Php 3.0.4
Php Php 3.0.3
Php Php 3.0.8
Php Php 3.0.5
Php Php
Php Php 4.0.0
Php Php 4.0.1
Php Php 4.2.0
Php Php 4.3.1
1 EDB exploit
642
VMScore
CVE-2021-3515
A shell injection flaw was found in pglogical in versions prior to 2.3.4 and prior to 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscri...
2ndquadrant Pglogical
641
VMScore
CVE-2020-13551
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM ...
Advantech Webaccess\\/scada 9.0.1
641
VMScore
CVE-2019-3466
The pg_ctlcluster script in postgresql-common in versions before 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
Postgresql Postgresql-common
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 19.04
Canonical Ubuntu Linux 19.10
Debian Debian Linux 9.0
Debian Debian Linux 10.0
641
VMScore
CVE-2016-1255
The pg_ctlcluster script in postgresql-common package in Debian wheezy prior to 134wheezy5, in Debian jessie prior to 165+deb8u2, in Debian unstable prior to 178, in Ubuntu 12.04 LTS prior to 129ubuntu1.2, in Ubuntu 14.04 LTS prior to 154ubuntu1.1, in Ubuntu 16.04 LTS prior to 17...
Debian Postgresql-common 11
Debian Postgresql-common 12
Debian Postgresql-common 13
Debian Postgresql-common 14
Debian Postgresql-common 28
Debian Postgresql-common 29
Debian Postgresql-common 30
Debian Postgresql-common 31
Debian Postgresql-common 44
Debian Postgresql-common 7
Debian Postgresql-common 9
Debian Postgresql-common 16
Debian Postgresql-common 18
Debian Postgresql-common 23
Debian Postgresql-common 45
Debian Postgresql-common 46
Debian Postgresql-common 47
Debian Postgresql-common 61
Debian Postgresql-common 62
Debian Postgresql-common 63
Debian Postgresql-common 64
Debian Postgresql-common 78
641
VMScore
CVE-2007-6601
The DBLink module in PostgreSQL 8.2 prior to 8.2.6, 8.1 prior to 8.1.11, 8.0 prior to 8.0.15, 7.4 prior to 7.4.19, and 7.3 prior to 7.3.21, when local trust or ident authentication is used, allows remote malicious users to gain privileges via unspecified vectors. NOTE: this issue...
Postgresql Postgresql 8.2
Postgresql Postgresql
Debian Debian Linux 3.1
Debian Debian Linux 4.0
Fedoraproject Fedora 8
Fedoraproject Fedora 7
641
VMScore
CVE-2002-1642
PostgreSQL 7.2.1 and 7.2.2 allows local users to delete transaction log (pg_clog) data and cause a denial of service (data loss) via the VACUUM command.
Postgresql Postgresql 7.2.1
Postgresql Postgresql 7.2.2
Postgresql Postgresql 7.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »