PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
INSERT ... ON CONFLICT DO UPDATE commands disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege. Even then, not all columns are subject to disclosure.
Vulnerable Versions: 9.5 - 10
PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.
End of life: 4/30/2022, Latest version: 9.6.24
End of life: 4/30/2022, Latest version: 9.6.24
End of life: 11/11/2021, Latest version: 9.6.24
End of life: 11/11/2021, Latest version: 9.6.24