Логотип exploitDog
bind:"CVE-2023-5869" OR bind:"CVE-2023-5870" OR bind:"CVE-2023-39417" OR bind:"CVE-2023-5868"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-5869" OR bind:"CVE-2023-5870" OR bind:"CVE-2023-39417" OR bind:"CVE-2023-5868"

Количество 59

Количество 59

nvd логотип

CVE-2023-5869

больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2023-5869

больше 1 года назад

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-5869

больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database user ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9625-p7pg-3cxg

больше 1 года назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7790

больше 1 года назад

ELSA-2023-7790: postgresql:10 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-7783

больше 1 года назад

ELSA-2023-7783: postgresql security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2023-07840

больше 1 года назад

Уязвимость функций array_append, array_prepend, array_subscript_handler системы управления базами данных PostgreSQL, связанная с целочисленным переполнением при модификации массивов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2023-5870

больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
EPSS: Низкий
redhat логотип

CVE-2023-5870

больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
EPSS: Низкий
nvd логотип

CVE-2023-5870

больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
EPSS: Низкий
msrc логотип

CVE-2023-5870

7 месяцев назад

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2023-5870

больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role th ...

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-5gp7-j4r7-g66f

больше 1 года назад

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
EPSS: Низкий
fstec логотип

BDU:2023-07904

больше 1 года назад

Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью рассылки сигналов процессам суперпользователей с помощью роли pg_signal_backend, позволяющая нарушителю вызвать отказ в обслуживании определенного фонового процесса

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2023-5868

больше 1 года назад

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2023-5868

больше 1 года назад

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-5868

больше 1 года назад

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2023-5868

больше 1 года назад

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2023-5868

больше 1 года назад

A memory disclosure vulnerability was found in PostgreSQL that allows ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2023-39417

почти 2 года назад

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-5869

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 8.8
2%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5869

A flaw was found in PostgreSQL that allows authenticated database user ...

CVSS3: 8.8
2%
Низкий
больше 1 года назад
github логотип
GHSA-9625-p7pg-3cxg

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
2%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2023-7790

ELSA-2023-7790: postgresql:10 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-7783

ELSA-2023-7783: postgresql security update (IMPORTANT)

больше 1 года назад
fstec логотип
BDU:2023-07840

Уязвимость функций array_append, array_prepend, array_subscript_handler системы управления базами данных PostgreSQL, связанная с целочисленным переполнением при модификации массивов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
2%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-5870

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-5870

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5870

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
1%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 4.4
1%
Низкий
7 месяцев назад
debian логотип
CVE-2023-5870

A flaw was found in PostgreSQL involving the pg_cancel_backend role th ...

CVSS3: 2.2
1%
Низкий
больше 1 года назад
github логотип
GHSA-5gp7-j4r7-g66f

A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVSS3: 2.2
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-07904

Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью рассылки сигналов процессам суперпользователей с помощью роли pg_signal_backend, позволяющая нарушителю вызвать отказ в обслуживании определенного фонового процесса

CVSS3: 2.2
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-5868

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
3%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-5868

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
3%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-5868

A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals without type designation can disclose bytes, potentially revealing notable and confidential information. This issue exists due to excessive data output in aggregate function calls, enabling remote users to read some portion of system memory.

CVSS3: 4.3
3%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 4.3
3%
Низкий
больше 1 года назад
debian логотип
CVE-2023-5868

A memory disclosure vulnerability was found in PostgreSQL that allows ...

CVSS3: 4.3
3%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-39417

IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVSS3: 7.5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу