Show filters
176 Total Results
Displaying 51-60 of 176
Sort by:
Attacker Value
Unknown
CVE-2015-0244
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
0
Attacker Value
Unknown
CVE-2015-0241
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when processing a numeric formatting template, which triggers a buffer over-read, or (2) crafted timestamp formatting template, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2014-8161
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.
0
Attacker Value
Unknown
CVE-2015-3167
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.
0
Attacker Value
Unknown
CVE-2015-3166
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
0
Attacker Value
Unknown
CVE-2019-3466
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
The pg_ctlcluster script in postgresql-common in versions prior to 210 didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.
0
Attacker Value
Unknown
CVE-2019-10211
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
0
Attacker Value
Unknown
CVE-2019-10208
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before 10.10 and 11.x before 11.5 where arbitrary SQL statements can be executed given a suitable SECURITY DEFINER function. An attacker, with EXECUTE permission on the function, can execute arbitrary SQL as the owner of the function.
0
Attacker Value
Unknown
CVE-2019-10210
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
0
Attacker Value
Unknown
CVE-2019-10209
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
0