VYPR

rpm package

suse/postgresql93-libs&distro=SUSE Linux Enterprise Desktop 12

pkg:rpm/suse/postgresql93-libs&distro=SUSE%20Linux%20Enterprise%20Desktop%2012

Vulnerabilities (9)

  • CVE-2015-0241Jan 27, 2020
    affected < 9.3.6-5.1fixed 9.3.6-5.1

    The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a (1) large number of digits when p

  • CVE-2015-0243Jan 27, 2020
    affected < 9.3.6-5.1fixed 9.3.6-5.1

    Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via unspecifie

  • CVE-2015-0244Jan 27, 2020
    affected < 9.3.6-5.1fixed 9.3.6-5.1

    PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter a

  • CVE-2014-8161Jan 27, 2020
    affected < 9.3.6-5.1fixed 9.3.6-5.1

    PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.

  • CVE-2015-3166Nov 20, 2019
    affected < 9.3.8-8.1fixed 9.3.8-8.1

    The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via u

  • CVE-2015-3167Nov 20, 2019
    affected < 9.3.8-8.1fixed 9.3.8-8.1

    contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

  • CVE-2015-5289Oct 26, 2015
    affected < 9.3.10-11.1fixed 9.3.10-11.1

    Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (2) jsonb values.

  • CVE-2015-5288Oct 26, 2015
    affected < 9.3.10-11.1fixed 9.3.10-11.1

    The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or read arbitrary server memory via a "too-short" salt.

  • CVE-2015-3165May 28, 2015
    affected < 9.3.8-8.1fixed 9.3.8-8.1

    Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire