8.8
CVSSv3

CVE-2021-32027

Published: 01/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in postgresql in versions prior to 13.3, prior to 12.7, prior to 11.12, prior to 10.17 and prior to 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql

redhat enterprise linux 7.0

redhat jboss enterprise application platform 7.0.0

redhat enterprise linux 8.0

redhat software collections -

Vendor Advisories

Several security issues were fixed in PostgreSQL ...
Multiple security issues have been discovered in the PostgreSQL database system, which could result in the execution of arbitrary code or disclosure of memory content For the stable distribution (buster), these problems have been fixed in version 1112-0+deb10u1 We recommend that you upgrade your postgresql-11 packages For the detailed security ...
A flaw was found in postgresql While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-32027) ...
A flaw was found in postgresql While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-32027) A flaw was found in postgresql U ...
A flaw was found in postgresql While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-32027) A flaw was found in postgresql U ...
A flaw was found in postgresql While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability (CVE-2021-32027) A flaw was found in postgresql U ...
A security issue was found in PostgreSQL before version 133 While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory ...
Multiple vulnerabilities have been found in Hitachi Ops Center Common Services CVE-2019-17195, CVE-2020-10718, CVE-2020-10734, CVE-2020-10746, CVE-2020-10776, CVE-2020-25638, CVE-2020-25689, CVE-2020-27822, CVE-2021-32027 Affected products and versions are listed below Please upgrade your version to the appropriate version ...
Multiple vulnerabilities have been found in Hitachi Ops Center Analyzer viewpoint CVE-2021-27306, CVE-2021-32027 Affected products and versions are listed below Please upgrade your version to the appropriate version ...
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution Missing overflow checks also let authenticated database users read a wide area of server memory The CVE-2021-32027 fix covered some attacks of this description, but it ...
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory ...

ICS Advisories

Hitachi Energy MicroSCADA X DMS600
Critical Infrastructure Sectors: Energy
Hitachi Energy MicroSCADA Pro/X SYS600
Critical Infrastructure Sectors: Energy