Search CVE reports
61 – 70 of 80 results
CVE-2016-0773
Medium prioritySome fixes available 4 of 6
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode...
5 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4, postgresql-9.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
postgresql-9.5 | — | — | — | — | Not affected |
CVE-2016-0766
Medium prioritySome fixes available 4 of 6
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which...
5 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4, postgresql-9.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
postgresql-9.5 | — | — | — | — | Not affected |
CVE-2015-5289
Medium prioritySome fixes available 4 of 5
Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-5288
Low prioritySome fixes available 4 of 5
The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9.4.5 allows attackers to cause a denial of service (server crash) or...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-3167
Medium prioritySome fixes available 6 of 7
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-3166
Medium prioritySome fixes available 6 of 7
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-3165
Medium prioritySome fixes available 6 of 7
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-0244
Medium prioritySome fixes available 5 of 6
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-0243
Medium prioritySome fixes available 5 of 6
Multiple buffer overflows in contrib/pgcrypto in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allow remote authenticated users to cause a denial of service (crash)...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |
CVE-2015-0241
Medium prioritySome fixes available 5 of 6
The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly execute...
4 affected packages
postgresql-8.4, postgresql-9.1, postgresql-9.3, postgresql-9.4
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
postgresql-8.4 | — | — | — | — | Not in release |
postgresql-9.1 | — | — | — | — | Not in release |
postgresql-9.3 | — | — | — | — | Not in release |
postgresql-9.4 | — | — | — | — | Not in release |