Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
postgresql vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2005-0245
Buffer overflow in gram.y for PostgreSQL 8.0.0 and previous versions may allow malicious users to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.
Postgresql Postgresql 8.0
Postgresql Postgresql
1 EDB exploit
NA
CVE-2021-43767
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attack...
Postgresql Postgresql
Postgresql Postgresql 14.0
465
VMScore
CVE-2000-1199
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.
Postgresql Postgresql 6.3.2
Postgresql Postgresql 6.5.3
1 EDB exploit
356
VMScore
CVE-2018-1052
Memory disclosure vulnerability in table partitioning was found in postgresql 10.x prior to 10.2, allowing an authenticated malicious user to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.
Postgresql Postgresql 10.1
Postgresql Postgresql 10.0
756
VMScore
CVE-2016-3065
The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL prior to 9.5.x prior to 9.5.2 allows malicious users to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of serv...
Postgresql Postgresql 9.5.1
Postgresql Postgresql 9.5
445
VMScore
CVE-2016-2193
PostgreSQL prior to 9.5.x prior to 9.5.2 does not properly maintain row-security status in cached plans, which might allow malicious users to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
Postgresql Postgresql 9.5.1
Postgresql Postgresql 9.5
641
VMScore
CVE-2016-1255
The pg_ctlcluster script in postgresql-common package in Debian wheezy prior to 134wheezy5, in Debian jessie prior to 165+deb8u2, in Debian unstable prior to 178, in Ubuntu 12.04 LTS prior to 129ubuntu1.2, in Ubuntu 14.04 LTS prior to 154ubuntu1.1, in Ubuntu 16.04 LTS prior to 17...
Debian Postgresql-common 11
Debian Postgresql-common 12
Debian Postgresql-common 13
Debian Postgresql-common 14
Debian Postgresql-common 28
Debian Postgresql-common 29
Debian Postgresql-common 30
Debian Postgresql-common 31
Debian Postgresql-common 44
Debian Postgresql-common 7
Debian Postgresql-common 9
Debian Postgresql-common 16
Debian Postgresql-common 18
Debian Postgresql-common 23
Debian Postgresql-common 45
Debian Postgresql-common 46
Debian Postgresql-common 47
Debian Postgresql-common 61
Debian Postgresql-common 62
Debian Postgresql-common 63
Debian Postgresql-common 64
Debian Postgresql-common 78
668
VMScore
CVE-2012-1618
Interaction error in the PostgreSQL JDBC driver prior to 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, w...
Postgresql Postgresql 9.1
Postgresql Postgresql Jdbc Driver 8.1
NA
CVE-2022-31197
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious c...
Postgresql Postgresql Jdbc Driver
Postgresql Postgresql Jdbc Driver 42.4.0
Postgresql Postgresql Jdbc Driver 42.4.1
Debian Debian Linux 10.0
Fedoraproject Fedora 35
Fedoraproject Fedora 36
NA
CVE-2022-41946
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will crea...
Postgresql Postgresql Jdbc Driver 42.5.0
Postgresql Postgresql Jdbc Driver
Debian Debian Linux 10.0
2 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »