Количество 59
Количество 59

CVE-2023-5870
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

CVE-2023-5870
CVE-2023-5870
A flaw was found in PostgreSQL involving the pg_cancel_backend role th ...
GHSA-5gp7-j4r7-g66f
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.

BDU:2023-07904
Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью рассылки сигналов процессам суперпользователей с помощью роли pg_signal_backend, позволяющая нарушителю вызвать отказ в обслуживании определенного фонового процесса

CVE-2023-39417
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVE-2023-39417
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVE-2023-39417
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

CVE-2023-39417
CVE-2023-39417
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in Po ...

SUSE-SU-2023:3384-1
Security update for postgresql15

SUSE-SU-2023:3348-1
Security update for postgresql15

SUSE-SU-2023:3346-1
Security update for postgresql12

SUSE-SU-2023:3345-1
Security update for postgresql15

SUSE-SU-2023:3344-1
Security update for postgresql15

SUSE-SU-2023:3343-1
Security update for postgresql15

SUSE-SU-2023:3341-1
Security update for postgresql12
GHSA-jx3x-j983-74m3
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser.

BDU:2023-04767
Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью SQL-инъекций в расширениях, позволяющая нарушителю выполнять произвольный SQL-запрос к базе данных

SUSE-SU-2023:3347-1
Security update for postgresql15
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-5870 A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack. | CVSS3: 2.2 | 1% Низкий | больше 1 года назад |
![]() | CVSS3: 4.4 | 1% Низкий | 7 месяцев назад | |
CVE-2023-5870 A flaw was found in PostgreSQL involving the pg_cancel_backend role th ... | CVSS3: 2.2 | 1% Низкий | больше 1 года назад | |
GHSA-5gp7-j4r7-g66f A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack. | CVSS3: 2.2 | 1% Низкий | больше 1 года назад | |
![]() | BDU:2023-07904 Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью рассылки сигналов процессам суперпользователей с помощью роли pg_signal_backend, позволяющая нарушителю вызвать отказ в обслуживании определенного фонового процесса | CVSS3: 2.2 | 1% Низкий | больше 1 года назад |
![]() | CVE-2023-39417 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
![]() | CVE-2023-39417 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
![]() | CVE-2023-39417 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
![]() | CVSS3: 8.8 | 1% Низкий | почти 2 года назад | |
CVE-2023-39417 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in Po ... | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3384-1 Security update for postgresql15 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3348-1 Security update for postgresql15 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3346-1 Security update for postgresql12 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3345-1 Security update for postgresql15 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3344-1 Security update for postgresql15 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3343-1 Security update for postgresql15 | 1% Низкий | почти 2 года назад | |
![]() | SUSE-SU-2023:3341-1 Security update for postgresql12 | 1% Низкий | почти 2 года назад | |
GHSA-jx3x-j983-74m3 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension, an attacker with database-level CREATE privilege can execute arbitrary code as the bootstrap superuser. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
![]() | BDU:2023-04767 Уязвимость системы управления базами данных PostgreSQL, связанная с возможностью SQL-инъекций в расширениях, позволяющая нарушителю выполнять произвольный SQL-запрос к базе данных | CVSS3: 7.5 | 1% Низкий | почти 2 года назад |
![]() | SUSE-SU-2023:3347-1 Security update for postgresql15 | почти 2 года назад |
Уязвимостей на страницу