pkg:Debian/postgresql-15
共 39 筆 CVEHIGH20MEDIUM15LOW4
✅ 檢查你的版本
所有已知漏洞
- from 0, < 15.18-0+deb12u1
- HIGH8.8CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryfrom 0, < 15.18-0+deb12u1
- HIGH8.8CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choicefrom 0, < 15.18-0+deb12u1
- from 0, < 15.18-0+deb12u1
- HIGH8.8CVE-2026-2006PostgreSQL missing validation of multibyte character length executes arbitrary codefrom 0, < 15.16-0+deb12u1
- from 0, < 15.16-0+deb12u1
- HIGH8.8CVE-2026-2004PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary codefrom 0, < 15.16-0+deb12u1
- HIGH8.8CVE-2025-8715PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target serverfrom 0, < 15.14-0+deb12u1
- HIGH8.8CVE-2025-8714PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientfrom 0, < 15.14-0+deb12u1
- from 0, < 15.9-0+deb12u1
- from 0, < 15.5-0+deb12u1
- HIGH8.8CVE-2023-39417Postgresql: extension script @substitutions@ within quoting allow sql injectionfrom 0, < 15.5-0+deb12u1
- HIGH8.8CVE-2023-39417Postgresql: extension script @substitutions@ within quoting allow sql injectionfrom 0, < 15.5-0+deb12u1
- HIGH8.1CVE-2025-1094PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validationfrom 0, < 15.11-0+deb12u1
- HIGH8.0CVE-2024-0985PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLfrom 0, < 15.6-0+deb12u1
- HIGH8.0CVE-2024-0985PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQLfrom 0, < 15.6-0+deb12u1
- from 0, < 15.18-0+deb12u1
- from 0, < 15.8-0+deb12u1
- from 0, < 15.8-0+deb12u1
- from 0, < 15.3-0+deb12u1
- from 0, < 15.18-0+deb12u1
- from 0, < 15.15-0+deb12u1
- MEDIUM5.9CVE-2025-4207PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationfrom 0, < 15.13-0+deb12u1
- from 0, < 15.18-0+deb12u1
- from 0, < 15.9-0+deb12u1
- from 0, < 15.9-0+deb12u1
- MEDIUM5.4CVE-2023-2455Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases w…from 0, < 15.3-0+deb12u1
- from 0, < 15.5-0+deb12u1
- from 0, < 15.18-0+deb12u1
- from 0, < 15.16-0+deb12u1
- from 0, < 15.16-0+deb12u1
- from 0, < 15.7-0+deb12u1
- from 0, < 15.5-0+deb12u1
- from 0, < 15.5-0+deb12u1
- from 0, < 15.9-0+deb12u1
- from 0, < 15.9-0+deb12u1
- LOW3.7CVE-2022-41862In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption.from 0, < 15.2-1
- from 0, < 15.15-0+deb12u1
- LOW3.1CVE-2025-8713PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child tablefrom 0, < 15.14-0+deb12u1