Known vulnerabilities in PostgreSQL 12

Software: PostgreSQL
Version: 12
Software CPE: cpe:2.3:a:postgresql_global_development_group:postgresql:*:*:*:*:*:*:*:*
Total vulnerabilities: 20
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting PostgreSQL version 12 PostgreSQL 12 is affected by 20 vulnerabilities: 2 high, 12 medium, 6 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU100514 - Improper Authorization
CVE-2024-10979
CWE-285 High
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 65 more
#VU100513 - Incorrect Privilege Assignment
CVE-2024-10978
CWE-266 Medium
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 46 more
#VU100512 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2024-10977
CWE-300 Low
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 34 more
#VU100511 - Improper Privilege Management
CVE-2024-10976
CWE-269 Medium
No
No
12.21, 13.17, 14.14, 15.9, 16.5, 17.1 15.11.2024 SB2024111502
SB2024111601
SB2024112245
and 47 more
#VU95605 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2024-7348
CWE-367 Low
No
No
12.20, 13.16, 14.13, 15.8, 16.4 08.08.2024 SB2024080866
SB2024080954
SB2024080955
and 63 more
#VU86275 - Improper Privilege Management
CVE-2024-0985
CWE-269 Medium
No
No
12.18, 13.14, 14.11, 15.6, 16.2 08.02.2024 SB2024020869
SB2024021617
SB2024021637
and 62 more
#VU82943 - Permissions, Privileges, and Access Controls
CVE-2023-5870
CWE-264 Low
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 54 more
#VU82942 - Integer overflow
CVE-2023-5869
CWE-190 High
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 70 more
#VU82941 - Exposure of sensitive information to an unauthorized actor
CVE-2023-5868
CWE-200 Low
No
No
11.22, 12.17, 13.13, 14.10, 15.5, 16.1 09.11.2023 SB2023110930
SB2023111320
SB2023111324
and 53 more
#VU79454 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39417
CWE-89 Medium
No
No
11.21, 12.16, 13.12, 14.9, 15.4 11.08.2023 SB2023081132
SB2023081715
SB2023081716
and 60 more
#VU76042 - Security Features
CVE-2023-2455
CWE-254 Low
No
No
11.20, 12.15, 13.11, 14.8, 15.3 11.05.2023 SB2023051138
SB2023051301
SB2023051528
and 61 more
#VU76041 - Permissions, Privileges, and Access Controls
CVE-2023-2454
CWE-264 Medium
No
No
11.20, 12.15, 13.11, 14.8, 15.3 11.05.2023 SB2023051138
SB2023051301
SB2023051528
and 55 more
#VU72088 - Out-of-bounds read
CVE-2022-41862
CWE-125 Medium
No
No
12.14, 13.10, 14.7, 15.2 09.02.2023 SB2023020953
SB2023021334
SB2023021335
and 47 more
#VU66429 - Permissions, Privileges, and Access Controls
CVE-2022-2625
CWE-264 Low
No
No
10.22, 11.17, 12.12, 13.8, 14.5 12.08.2022 SB2022081212
SB2022081848
SB2022082547
and 40 more
#VU63126 - Permissions, Privileges, and Access Controls
CVE-2022-1552
CWE-264 Medium
No
No
10.21, 11.16, 12.11, 13.7, 14.3 12.05.2022 SB2022051213
SB2022051303
SB2022051304
and 48 more
#VU58114 - Missing Encryption of Sensitive Data
CVE-2021-23222
CWE-311 Medium
No
No
9.6.24, 10.19, 11.14, 12.9, 13.5, 14.1 11.11.2021 SB2021111139
SB2021111708
SB2021111709
and 29 more
#VU58113 - Missing Encryption of Sensitive Data
CVE-2021-23214
CWE-311 Medium
No
No
9.6.24, 10.19, 11.14, 12.9, 13.5, 14.1 11.11.2021 SB2021111139
SB2021111708
SB2021111709
and 34 more
#VU53233 - Missing release of memory after effective lifetime
CVE-2021-32029
CWE-401 Medium
No
No
11.12, 12.7, 13.3 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 18 more
#VU53232 - Missing release of memory after effective lifetime
CVE-2021-32028
CWE-401 Medium
No
No
9.6.22, 10.17, 11.12, 12.7, 13.3 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 41 more
#VU53231 - Integer overflow
CVE-2021-32027
CWE-190 Medium
No
No
9.6.22, 10.17, 11.12, 12.7, 13.3 13.05.2021 SB2021051316
SB2021051605
SB2021052507
and 43 more