Search CVE reports
71 – 74 of 74 results
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a...
5 affected packages
postgresql-10, postgresql-9.1, postgresql-9.3, postgresql-9.5, postgresql-9.6
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| postgresql-10 | — | — | — | — | Not affected |
| postgresql-9.1 | — | — | — | — | Not in release |
| postgresql-9.3 | — | — | — | — | Not in release |
| postgresql-9.5 | — | — | — | — | Not in release |
| postgresql-9.6 | — | — | — | — | Not in release |
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners...
5 affected packages
postgresql-10, postgresql-9.5, postgresql-9.1, postgresql-9.3, postgresql-9.6
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| postgresql-10 | — | — | — | — | Not affected |
| postgresql-9.5 | — | — | — | — | Not in release |
| postgresql-9.1 | — | — | — | — | Not in release |
| postgresql-9.3 | — | — | — | — | Not in release |
| postgresql-9.6 | — | — | — | — | Not in release |
PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
5 affected packages
postgresql-10, postgresql-9.1, postgresql-9.3, postgresql-9.5, postgresql-9.6
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| postgresql-10 | — | — | — | — | Not affected |
| postgresql-9.1 | — | — | — | — | Not in release |
| postgresql-9.3 | — | — | — | — | Not in release |
| postgresql-9.5 | — | — | — | — | Not in release |
| postgresql-9.6 | — | — | — | — | Not in release |
Some fixes available 3 of 4
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information...
5 affected packages
postgresql-9.1, postgresql-9.3, postgresql-10, postgresql-9.5, postgresql-9.6
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| postgresql-9.1 | — | — | — | — | Not in release |
| postgresql-9.3 | — | — | — | — | Not in release |
| postgresql-10 | — | — | — | — | Not affected |
| postgresql-9.5 | — | — | — | — | Not in release |
| postgresql-9.6 | — | — | — | — | Not in release |