Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 300

Количество 1 300

oracle-oval логотип

ELSA-2022-1891

больше 4 лет назад

ELSA-2022-1891: libpq security update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2017-2860

почти 9 лет назад

ELSA-2017-2860: postgresql security update (MODERATE)

EPSS: Средний
oracle-oval логотип

ELSA-2016-0347

больше 10 лет назад

ELSA-2016-0347: postgresql security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2016-0346

больше 10 лет назад

ELSA-2016-0346: postgresql security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-2081

почти 11 лет назад

ELSA-2015-2081: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1264

около 14 лет назад

ELSA-2012-1264: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-0198

больше 15 лет назад

ELSA-2011-0198: postgresql84 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2011-0197

больше 15 лет назад

ELSA-2011-0197: postgresql security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2010-0742

почти 16 лет назад

ELSA-2010-0742: postgresql and postgresql84 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2026-6638

4 месяца назад

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2026-6638

4 месяца назад

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-6638

4 месяца назад

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-6638

4 месяца назад

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2026-6637

4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-6637

4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2026-6637

4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-6637

4 месяца назад

Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6575

4 месяца назад

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2026-6575

4 месяца назад

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-6575

4 месяца назад

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-1891

ELSA-2022-1891: libpq security update (LOW)

2%
Низкий
больше 4 лет назад
oracle-oval логотип
ELSA-2017-2860

ELSA-2017-2860: postgresql security update (MODERATE)

62%
Средний
почти 9 лет назад
oracle-oval логотип
ELSA-2016-0347

ELSA-2016-0347: postgresql security update (IMPORTANT)

7%
Низкий
больше 10 лет назад
oracle-oval логотип
ELSA-2016-0346

ELSA-2016-0346: postgresql security update (IMPORTANT)

7%
Низкий
больше 10 лет назад
oracle-oval логотип
ELSA-2015-2081

ELSA-2015-2081: postgresql security update (MODERATE)

5%
Низкий
почти 11 лет назад
oracle-oval логотип
ELSA-2012-1264

ELSA-2012-1264: postgresql security update (MODERATE)

3%
Низкий
около 14 лет назад
oracle-oval логотип
ELSA-2011-0198

ELSA-2011-0198: postgresql84 security update (MODERATE)

5%
Низкий
больше 15 лет назад
oracle-oval логотип
ELSA-2011-0197

ELSA-2011-0197: postgresql security update (MODERATE)

5%
Низкий
больше 15 лет назад
oracle-oval логотип
ELSA-2010-0742

ELSA-2010-0742: postgresql and postgresql84 security update (MODERATE)

3%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

CVSS3: 3.7
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6638

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... ...

CVSS3: 3.7
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6637

Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...

CVSS3: 8.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-6575

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6575

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6575

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

CVSS3: 4.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу