Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 67

Количество 67

ubuntu логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-6478

4 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreS ...

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2026:28208

3 месяца назад

Important: postgresql:13 security update

EPSS: Низкий
github логотип

GHSA-r6v6-v5r9-3ggh

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-28208

3 месяца назад

ELSA-2026-28208: postgresql:13 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:28999

3 месяца назад

Important: postgresql:12 security update

EPSS: Низкий
rocky логотип

RLSA-2026:28143

3 месяца назад

Important: postgresql:16 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28999

3 месяца назад

ELSA-2026-28999: postgresql:12 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28143

3 месяца назад

ELSA-2026-28143: postgresql:16 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-26181

3 месяца назад

ELSA-2026-26181: postgresql:15 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:28037

3 месяца назад

Important: postgresql:15 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27743

3 месяца назад

Important: postgresql16 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27742

3 месяца назад

Important: postgresql18 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27738

3 месяца назад

Important: libpq security update

EPSS: Низкий
rocky логотип

RLSA-2026:26204

3 месяца назад

Important: postgresql:18 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26203

3 месяца назад

Important: postgresql:16 security update

EPSS: Низкий
rocky логотип

RLSA-2026:26181

3 месяца назад

Important: postgresql:15 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-6478

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreS ...

CVSS3: 6.5
1%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:28208

Important: postgresql:13 security update

1%
Низкий
3 месяца назад
github логотип
GHSA-r6v6-v5r9-3ggh

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-28208

ELSA-2026-28208: postgresql:13 security update (IMPORTANT)

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:28999

Important: postgresql:12 security update

3 месяца назад
rocky логотип
RLSA-2026:28143

Important: postgresql:16 security update

3 месяца назад
oracle-oval логотип
ELSA-2026-28999

ELSA-2026-28999: postgresql:12 security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-28143

ELSA-2026-28143: postgresql:16 security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-26181

ELSA-2026-26181: postgresql:15 security update (IMPORTANT)

3 месяца назад
rocky логотип
RLSA-2026:28037

Important: postgresql:15 security update

3 месяца назад
rocky логотип
RLSA-2026:27743

Important: postgresql16 security update

3 месяца назад
rocky логотип
RLSA-2026:27742

Important: postgresql18 security update

3 месяца назад
rocky логотип
RLSA-2026:27738

Important: libpq security update

3 месяца назад
rocky логотип
RLSA-2026:26204

Important: postgresql:18 security update

3 месяца назад
rocky логотип
RLSA-2026:26203

Important: postgresql:16 security update

3 месяца назад
rocky логотип
RLSA-2026:26181

Important: postgresql:15 security update

3 месяца назад

Уязвимостей на страницу