Overview
- suse
- postgresql-init
01 Mar 2018
Published
16 Sep 2024
Updated
CVSS v3.0
HIGH (7.3)
EPSS
0.81%
KEV
Description
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Red Hat, Inc.
- postgresql
22 Nov 2017
Published
16 Sep 2024
Updated
CVSS
Pending
EPSS
0.86%
KEV
Description
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- The PostgreSQL Global Development Group
- postgresql
09 Feb 2018
Published
17 Sep 2024
Updated
CVSS
Pending
EPSS
0.08%
KEV
Description
In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- PostgreSQL Global Development Group
- PostgreSQL
20 Nov 2019
Published
06 Aug 2024
Updated
CVSS
Pending
EPSS
5.39%
KEV
Description
The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
Description
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- The PostgreSQL Global Development Group
- PostgreSQL
12 May 2017
Published
05 Aug 2024
Updated
CVSS
Pending
EPSS
1.32%
KEV
Description
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- The PostgreSQL Global Development Group
- postgresql
02 Mar 2018
Published
17 Sep 2024
Updated
CVSS
Pending
EPSS
82.69%
KEV
Description
A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database. Versions 9.3 through 10 are affected.
Statistics
- 1 Post
Last activity: 3 hours ago