Search CVE reports


Toggle filters

71 – 80 of 133 results

Status is adjusted based on your filters.


CVE-2022-1552

Medium priority
Fixed

A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is maintaining another user's objects. The Autovacuum, REINDEX, CREATE INDEX, REFRESH MATERIALIZED VIEW, CLUSTER,...

7 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-14, postgresql-9.1...

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-14 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show all 7 packages Show less packages

CVE-2021-23222

Medium priority
Fixed

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption.

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-23214

Medium priority
Fixed

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite...

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-3677

Medium priority
Fixed

A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the...

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-32027

Medium priority
Fixed

A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary...

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-32029

Medium priority
Fixed

A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from this vulnerability is to data...

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-32028

Medium priority
Fixed

A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an authenticated database user could read arbitrary bytes of server memory. The highest threat from...

6 affected packages

postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show less packages

CVE-2021-3449

High priority
Fixed

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial...

10 affected packages

edk2, nodejs, openssl, openssl1.0, postgresql-10...

Package 20.04 LTS
edk2 Not affected
nodejs Not affected
openssl Fixed
openssl1.0 Not in release
postgresql-10 Not in release
postgresql-12 Fixed
postgresql-13 Not in release
postgresql-9.1 Not in release
postgresql-9.3 Not in release
postgresql-9.5 Not in release
Show all 10 packages Show less packages

CVE-2019-10128

Medium priority

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for EnterpriseDB-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it...

5 affected packages

postgresql-10, postgresql-11, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 —
postgresql-11 —
postgresql-9.1 —
postgresql-9.3 —
postgresql-9.5 —
Show less packages

CVE-2019-10127

Medium priority

A vulnerability was found in postgresql versions 11.x prior to 11.3. The Windows installer for BigSQL-supplied PostgreSQL does not lock down the ACL of the binary installation directory or the ACL of the data directory; it keeps...

5 affected packages

postgresql-10, postgresql-11, postgresql-9.1, postgresql-9.3, postgresql-9.5

Package 20.04 LTS
postgresql-10 —
postgresql-11 —
postgresql-9.1 —
postgresql-9.3 —
postgresql-9.5 —
Show less packages