Количество 9
Количество 9
BDU:2026-11977
Уязвимость механизма логического декодирования (logical decoding) системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVE-2026-6471
PostgreSQL logical decoding can dlopen arbitrary file
CVE-2026-6471
Missing authorization in PostgreSQL logical decoding allows a non-supe ...
GHSA-r26j-h78w-pjqm
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
SUSE-SU-2026:3793-1
Security update for postgresql14
SUSE-SU-2026:3794-1
Security update for postgresql16
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-11977 Уязвимость механизма логического декодирования (logical decoding) системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
CVE-2026-6471 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
CVE-2026-6471 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
CVE-2026-6471 Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected. | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
CVE-2026-6471 PostgreSQL logical decoding can dlopen arbitrary file | 0% Низкий | 18 дней назад | ||
CVE-2026-6471 Missing authorization in PostgreSQL logical decoding allows a non-supe ... | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
GHSA-r26j-h78w-pjqm Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | CVSS3: 7.2 | 0% Низкий | 20 дней назад | |
SUSE-SU-2026:3793-1 Security update for postgresql14 | 8 дней назад | |||
SUSE-SU-2026:3794-1 Security update for postgresql16 | 8 дней назад |
Уязвимостей на страницу