9
CVSSv2

CVE-2016-0766

Published: 17/02/2016 Updated: 19/01/2023
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

PostgreSQL prior to 9.1.20, 9.2.x prior to 9.2.15, 9.3.x prior to 9.3.11, 9.4.x prior to 9.4.6, and 9.5.x prior to 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows malicious users to gain privileges via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 9.5

postgresql postgresql

canonical ubuntu linux 12.04

debian debian linux 8.0

debian debian linux 7.0

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

Vendor Advisories

PostgreSQL could be made to crash or run programs if it handled specially crafted data ...
Several vulnerabilities have been found in PostgreSQL-94, a SQL database system CVE-2016-0766 A privilege escalation vulnerability for users of PL/Java was discovered Certain custom configuration settings (GUCs) for PL/Java will now be modifiable only by the database superuser to mitigate this issue CVE-2016-0773 Tom Lane a ...
Several vulnerabilities have been found in PostgreSQL-91, a SQL database system CVE-2015-5288 Josh Kupershmidt discovered a vulnerability in the crypt() function in the pgCrypto extension Certain invalid salt arguments can cause the server to crash or to disclose a few bytes of server memory CVE-2016-0766 A privilege escalation ...