Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 165 CRITICAL 7 HIGH 70 MEDIUM 81 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • 商用ライセンス有り
  • オープンソース
  • PostgreSQL Licence

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
91 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 8 5 0
92 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 11 7 1
93 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 13 8 1
94 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 17 13 1
95 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 20 14 1
96 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 24 15 1
97 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 26 12 0
98 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 44 40 0
99 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 36 51 3
100 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 36 41 4
101 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 26 23 2
102 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 26 25 1
103 PostgreSQL - - 4 22 17 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
91 -
6.5
MEDIUM Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remot… CWE-189
Numeric Errors
CVE-2014-0064 cpe:2.3:a:postgresql:postgresql:9.3:*
cpe:2.3:a:postgresql:postgresql:9.3.2:*
cpe:2.3:a:postgresql:postgresql:9.3…
8.4.19 2024-11-21 11:01
2014-03-31
Show GitHub Exploit DB Packet Storm
92 -
6.5
MEDIUM Multiple stack-based buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to cause a den… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-0063 cpe:2.3:a:postgresql:postgresql:9.3:*
cpe:2.3:a:postgresql:postgresql:9.3.2:*
cpe:2.3:a:postgresql:postgresql:9.3…
8.4.19 2024-11-21 11:01
2014-03-31
Show GitHub Exploit DB Packet Storm
93 -
4.9
MEDIUM Race condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow… CWE-362
Race Condition
CVE-2014-0062 cpe:2.3:a:postgresql:postgresql:9.3:*
cpe:2.3:a:postgresql:postgresql:9.3.2:*
cpe:2.3:a:postgresql:postgresql:9.3…
8.4.19 2024-11-21 11:01
2014-03-31
Show GitHub Exploit DB Packet Storm
94 -
6.5
MEDIUM The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0061 cpe:2.3:a:postgresql:postgresql:9.3:*
cpe:2.3:a:postgresql:postgresql:9.3.2:*
cpe:2.3:a:postgresql:postgresql:9.3…
8.4.19 2024-11-21 11:01
2014-03-31
Show GitHub Exploit DB Packet Storm
95 -
4.0
MEDIUM PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly enforce the ADMIN OPTION restriction, which allows remote authenticate… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-0060 cpe:2.3:a:postgresql:postgresql:9.3:*
cpe:2.3:a:postgresql:postgresql:9.3.2:*
cpe:2.3:a:postgresql:postgresql:9.3…
8.4.19 2024-11-21 11:01
2014-03-31
Show GitHub Exploit DB Packet Storm
96 -
10.0
HIGH PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides the superuser password to scripts related to "graph… CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1903 cpe:2.3:a:postgresql:postgresql:9.2:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*
cpe:2.3:a:postgresql:postgresql:9.2…
2024-11-21 10:50
2013-04-5
Show GitHub Exploit DB Packet Storm
97 -
10.0
HIGH PostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary files with predictable filenames, which has unspecif… NVD-CWE-Other
CVE-2013-1902 cpe:2.3:a:postgresql:postgresql:9.2:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*
cpe:2.3:a:postgresql:postgresql:9.2…
2024-11-21 10:50
2013-04-5
Show GitHub Exploit DB Packet Storm
98 -
4.0
MEDIUM PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) … CWE-264
Permissions, Privileges, and Access Controls
CVE-2013-1901 cpe:2.3:a:postgresql:postgresql:9.2:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*
cpe:2.3:a:postgresql:postgresql:9.2…
2024-11-21 10:50
2013-04-5
Show GitHub Exploit DB Packet Storm
99 -
8.5
HIGH PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated us… CWE-189
Numeric Errors
CVE-2013-1900 cpe:2.3:a:postgresql:postgresql:9.2:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*
cpe:2.3:a:postgresql:postgresql:9.2…
2024-11-21 10:50
2013-04-5
Show GitHub Exploit DB Packet Storm
100 -
6.5
MEDIUM Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remot… CWE-94
Code Injection
CVE-2013-1899 cpe:2.3:a:postgresql:postgresql:9.2:*
cpe:2.3:a:postgresql:postgresql:9.2.3:*
cpe:2.3:a:postgresql:postgresql:9.2…
2024-11-21 10:50
2013-04-5
Show GitHub Exploit DB Packet Storm