Количество 36
Количество 36
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
PostgreSQL refint allows stack buffer overflow and SQL injection
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...
GHSA-96xx-m79q-xh44
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
BDU:2026-07094
Уязвимость модуля refint системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код
ROS-20260709-73-0001
Уязвимость postgresql16
ROS-20260706-73-0047
Уязвимость postgresql18-1c
ROS-20260706-73-0046
Уязвимость postgresql18
ROS-20260706-73-0045
Уязвимость postgresql17-1c
ROS-20260706-73-0044
Уязвимость postgresql17
ROS-20260706-73-0043
Уязвимость postgresql15-1c
ROS-20260706-73-0042
Уязвимость postgresql15
ROS-20260706-73-0041
Уязвимость postgresql14
ROS-20260706-73-0040
Уязвимость postgresql-1c
openSUSE-SU-2026:21103-1
Security update for postgresql15
openSUSE-SU-2026:21102-1
Security update for postgresql14
SUSE-SU-2026:2117-1
Security update for postgresql14
SUSE-SU-2026:2086-1
Security update for postgresql14
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ... | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
GHSA-96xx-m79q-xh44 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
BDU:2026-07094 Уязвимость модуля refint системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
ROS-20260709-73-0001 Уязвимость postgresql16 | CVSS3: 8.8 | 0% Низкий | 22 дня назад | |
ROS-20260706-73-0047 Уязвимость postgresql18-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0046 Уязвимость postgresql18 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0045 Уязвимость postgresql17-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0044 Уязвимость postgresql17 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0043 Уязвимость postgresql15-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0042 Уязвимость postgresql15 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0041 Уязвимость postgresql14 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0040 Уязвимость postgresql-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
openSUSE-SU-2026:21103-1 Security update for postgresql15 | около 1 месяца назад | |||
openSUSE-SU-2026:21102-1 Security update for postgresql14 | около 1 месяца назад | |||
SUSE-SU-2026:2117-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2086-1 Security update for postgresql14 | 2 месяца назад |
Уязвимостей на страницу