VYPR

PostgreSQL

by PostgreSQL

Source repositories

CVEs (214)

  • CVE-2025-8713LowAug 14, 2025
    risk 0.20cvss 3.1epss 0.00

    PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data…

  • CVE-2024-10977LowNov 14, 2024
    risk 0.20cvss 3.1epss 0.00

    Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper…

  • CVE-2024-4317LowMay 14, 2024
    risk 0.20cvss 3.1epss 0.01

    Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the…

  • CVE-2023-39418LowAug 11, 2023
    risk 0.20cvss 3.1epss 0.01

    A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a user could store such rows.

  • CVE-2020-1720LowMar 17, 2020
    risk 0.20cvss 3.1epss 0.01

    A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects such as function, triggers, et al., leading to database…

  • CVE-2026-6469LowAug 13, 2026
    risk 0.18cvss 3.8epss 0.00

    Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies…

  • CVE-2026-16241LowAug 13, 2026
    risk 0.18cvss 3.8epss 0.00

    Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or…

  • CVE-2026-14673LowAug 13, 2026
    risk 0.18cvss 3.8epss 0.00

    Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within…

  • CVE-2026-6638LowMay 14, 2026
    risk 0.17cvss 3.7epss 0.00

    SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major…

  • CVE-2023-5870LowDec 10, 2023
    risk 0.15cvss 2.2epss 0.03

    A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient…

  • CVE-2019-10209LowOct 29, 2019
    risk 0.14cvss 2.2epss 0.01

    Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.

  • CVE-2013-1899Apr 4, 2013
    risk 0.07cvss —epss 0.54

    Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration settings and execute arbitrary…

  • CVE-2007-3280Jun 19, 2007
    risk 0.05cvss —epss 0.25

    The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by…

  • CVE-2010-0733Mar 19, 2010
    risk 0.04cvss —epss 0.07

    Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with many LEFT JOIN clauses, related to certain hashtable size…

  • CVE-2010-0442Feb 2, 2010
    risk 0.04cvss —epss 0.13

    The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as…

  • CVE-2009-0922Mar 17, 2009
    risk 0.04cvss —epss 0.10

    PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using…

  • CVE-2005-0245Feb 1, 2005
    risk 0.04cvss —epss 0.14

    Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005-0247.

  • CVE-2000-1199Aug 31, 2001
    risk 0.03cvss —epss 0.01

    PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

  • CVE-2015-3165May 28, 2015
    risk 0.01cvss —epss 0.09

    Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will…

  • CVE-2009-3231Sep 17, 2009
    risk 0.01cvss —epss 0.08

    The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

Page 7 of 11