Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 165 CRITICAL 7 HIGH 70 MEDIUM 81 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • 商用ライセンス有り
  • オープンソース
  • PostgreSQL Licence

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
111 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 8 5 0
112 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 11 7 1
113 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 13 8 1
114 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 17 13 1
115 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 20 14 1
116 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 24 15 1
117 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 26 12 0
118 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 44 40 0
119 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 36 51 3
120 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 36 41 4
121 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 26 23 2
122 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 26 25 1
123 PostgreSQL - - 4 22 17 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
111 -
6.5
MEDIUM Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.2… CWE-189
Numeric Errors
CVE-2010-4015 cpe:2.3:a:postgresql:postgresql:9.0:*
cpe:2.3:a:postgresql:postgresql:9.0.2:*
cpe:2.3:a:postgresql:postgresql:9.0…
2024-11-21 10:20
2011-02-2
Show GitHub Exploit DB Packet Storm
112 -
6.0
MEDIUM The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not prope… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3433 cpe:2.3:a:postgresql:postgresql:9.0:*
cpe:2.3:a:postgresql:postgresql:8.4:*
cpe:2.3:a:postgresql:postgresql:8.4.4…
2024-11-21 10:18
2010-10-7
Show GitHub Exploit DB Packet Storm
113 -
8.5
HIGH PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 does not properly restrict PL/perl procedure… CWE-94
Code Injection
CVE-2010-1169 cpe:2.3:a:postgresql:postgresql:9.0.0:beta1
cpe:2.3:a:postgresql:postgresql:8.4:*
cpe:2.3:a:postgresql:postgresql…
2017-09-19 10:30
2010-05-20
Show GitHub Exploit DB Packet Storm
114 -
6.0
MEDIUM The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4.4, and 9.0 Beta before 9.0 Beta 2 loads Tcl code … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1170 cpe:2.3:a:postgresql:postgresql:9.0.0:beta1
cpe:2.3:a:postgresql:postgresql:8.4:*
cpe:2.3:a:postgresql:postgresql…
2017-09-19 10:30
2010-05-20
Show GitHub Exploit DB Packet Storm
115 -
8.5
HIGH The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 be… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1447 cpe:2.3:a:postgresql:postgresql:9.0.0:beta1
cpe:2.3:a:postgresql:postgresql:8.4:*
cpe:2.3:a:postgresql:postgresql…
2017-09-19 10:30
2010-05-20
Show GitHub Exploit DB Packet Storm
116 -
5.5
MEDIUM PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-1975 cpe:2.3:a:postgresql:postgresql:9.0.0:beta1
cpe:2.3:a:postgresql:postgresql:8.4:*
cpe:2.3:a:postgresql:postgresql…
2017-09-19 10:30
2010-05-20
Show GitHub Exploit DB Packet Storm
117 -
3.5
LOW Integer overflow in src/backend/executor/nodeHash.c in PostgreSQL 8.4.1 and earlier, and 8.5 through 8.5alpha2, allows remote authenticated users to cause a denial of service (daemon crash) via a SEL… CWE-189
Numeric Errors
CVE-2010-0733 cpe:2.3:a:postgresql:postgresql:8.5:alpha2
cpe:2.3:a:postgresql:postgresql:8.5:alpha1
cpe:2.3:a:postgresql:postgr…
8.4.1 2023-02-13 13:16
2010-03-20
Show GitHub Exploit DB Packet Storm
118 -
6.5
MEDIUM The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other im… CWE-189
Numeric Errors
CVE-2010-0442 cpe:2.3:a:postgresql:postgresql:*:* 8.4
8.3
8.2
8.1
8.0
7.4










8.4.3
8.3.10
8.2.16
8.1.20
8.0.24
7.4.28
2023-02-25 03:45
2010-02-3
Show GitHub Exploit DB Packet Storm
119 -
6.5
MEDIUM PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution… NVD-CWE-Other
CVE-2009-4136 cpe:2.3:a:postgresql:postgresql:8.4.1:*
cpe:2.3:a:postgresql:postgresql:8.3.8:*
cpe:2.3:a:postgresql:postgresql:8…
2026-04-23 09:35
2009-12-16
Show GitHub Exploit DB Packet Storm
120 -
5.8
MEDIUM PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in… CWE-310
Cryptographic Issues
CVE-2009-4034 cpe:2.3:a:postgresql:postgresql:8.4.1:*
cpe:2.3:a:postgresql:postgresql:8.3.8:*
cpe:2.3:a:postgresql:postgresql:8…
2026-04-23 09:35
2009-12-16
Show GitHub Exploit DB Packet Storm