Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PostgreSQL Number Of NVD 165 CRITICAL 7 HIGH 70 MEDIUM 81 LOW 7
URL https://www.postgresql.org/
Explanation PostgreSQL is an object-relational database management system (ORDBMS) based on POSTGRES, Version 4.2, developed by the Department of Computer Science at the University of California, Berkeley.

Extracted from [https://www.postgresql.jp/document/11/html/intro-whatis.html]

From version 10 onwards, the integer part represents major versions and the decimal part represents minor updates.

Every year, a major version including new features is released.
Minor releases with bugs and security fixes will be released at least once every three months, if necessary.
Unscheduled releases will be made for urgent security issues.
Support is provided for five years after the major version is released.
Tag
  • 商用ライセンス有り
  • オープンソース
  • PostgreSQL Licence

Add Information URL
No Type Name URL
1 https://www.postgresql.org/support/versioning/
2 https://wiki.postgresql.org/wiki/Main_Page
3 https://www.postgresql.jp/
4 https://www.postgresql.org/download/

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
151 PostgreSQL 16 16.11 Nov. 13, 2025 Sept. 14, 2023 Sept. 9, 2028 0 8 5 0
152 PostgreSQL 15 15.15 Nov. 13, 2025 Jan. 13, 2022 Nov. 11, 2027 0 11 7 1
153 PostgreSQL 14 14.20 Nov. 13, 2025 May 15, 2021 Nov. 12, 2026 0 13 8 1
154 PostgreSQL 13 13.23 Nov. 13, 2025 Sept. 24, 2020 Nov. 23, 2025 0 17 13 1
155 PostgreSQL 12 12.22 Nov. 21, 2024 Oct. 3, 2019 Nov. 14, 2024 0 20 14 1
156 PostgreSQL 11 11.22 Nov. 9, 2023 Oct. 18, 2018 Nov. 9, 2023 2 24 15 1
157 PostgreSQL 10 10.23 Nov. 10, 2022 Oct. 5, 2017 Nov. 10, 2022 3 26 12 0
158 PostgreSQL 9 9.6.24 Sept. 20, 2010 Oct. 8, 2015 6 44 40 0
159 PostgreSQL 8 8.0.9 Jan. 19, 2005 July 24, 2014 4 36 51 3
160 PostgreSQL 7 7.0.3 May 8, 2000 May 8, 2005 4 36 41 4
161 PostgreSQL 6 6.5.3 Jan. 29, 1997 June 9, 2004 4 26 23 2
162 PostgreSQL 1 1.09 Nov. 4, 1996 Jan. 1, 2000 4 26 25 1
163 PostgreSQL - - 4 22 17 1
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
151 -
7.5
HIGH Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based … NVD-CWE-Other
CVE-2005-0245 cpe:2.3:a:postgresql:postgresql:8.0:*
cpe:2.3:a:postgresql:postgresql:*:*
7.3
7.4


7.3.10
7.4.7
2023-01-20 05:13
2005-02-1
Show GitHub Exploit DB Packet Storm
152 -
5.0
MEDIUM Buffer overflow in the ODBC driver for PostgreSQL before 7.2.1 allows remote attackers to cause a denial of service (crash). NVD-CWE-Other
CVE-2004-0547 cpe:2.3:a:postgresql:postgresql:7.2.1:* 2017-07-11 10:30
2004-08-6
Show GitHub Exploit DB Packet Storm
153 -
7.5
HIGH Buffer overflow in to_ascii for PostgreSQL 7.2.x, and 7.3.x before 7.3.4, allows remote attackers to execute arbitrary code. NVD-CWE-Other
CVE-2003-0901 cpe:2.3:a:postgresql:postgresql:7.3:*
cpe:2.3:a:postgresql:postgresql:7.3.3:*
cpe:2.3:a:postgresql:postgresql:7.3…
2008-09-6 05:35
2003-11-3
Show GitHub Exploit DB Packet Storm
154 -
7.5
HIGH Vulnerability in the cash_words() function for PostgreSQL 7.2 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a large negative argument, possibly t… NVD-CWE-Other
CVE-2002-1397 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.1:*
cpe:2.3:a:postgresql:postgresql:7.1.3…
2017-07-11 10:29
2003-01-17
Show GitHub Exploit DB Packet Storm
155 -
4.6
MEDIUM Buffer overflow in the date parser for PostgreSQL before 7.2.2 allows attackers to cause a denial of service and possibly execute arbitrary code via a long date string, aka a vulnerability "in handli… NVD-CWE-Other
CVE-2002-1398 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
156 -
10.0
HIGH Unknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknown impact, based on an invalid integer input which … NVD-CWE-Other
CVE-2002-1399 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
157 -
7.5
HIGH Heap-based buffer overflow in the repeat() function for PostgreSQL before 7.2.2 allows attackers to execute arbitrary code by causing repeat() to generate a large string. NVD-CWE-Other
CVE-2002-1400 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
158 -
6.5
MEDIUM Buffer overflows in (1) circle_poly, (2) path_encode and (3) path_add (also incorrectly identified as path_addr) for PostgreSQL 7.2.3 and earlier allow attackers to cause a denial of service and poss… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2002-1401 cpe:2.3:a:postgresql:postgresql:7.2:*
cpe:2.3:a:postgresql:postgresql:7.2.3:*
cpe:2.3:a:postgresql:postgresql:7.2…
2008-09-10 13:00
2003-01-17
Show GitHub Exploit DB Packet Storm
159 -
4.6
MEDIUM Buffer overflows in the (1) TZ and (2) SET TIME ZONE enivronment variables for PostgreSQL 7.2.1 and earlier allow local users to cause a denial of service and possibly execute arbitrary code. NVD-CWE-Other
CVE-2002-1402 cpe:2.3:a:postgresql:postgresql:7.2.1:*
cpe:2.3:a:postgresql:postgresql:7.1:*
cpe:2.3:a:postgresql:postgresql:7.1…
2016-10-18 11:26
2003-01-17
Show GitHub Exploit DB Packet Storm
160 7.5
5.0
HIGH
Network
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack. CWE-916
 Use of Password Hash With Insufficient Computational Effort
CVE-2002-1657 cpe:2.3:a:postgresql:postgresql:7.3.19:* 2024-02-9 12:06
2002-12-31
Show GitHub Exploit DB Packet Storm