Количество 72
Количество 72
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6473
PostgreSQL server undersizes allocations, via integer wraparound
CVE-2026-6473
Integer wraparound in multiple PostgreSQL server features allows an un ...
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
PostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreS ...
GHSA-8rqw-w7xq-566r
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
BDU:2026-07102
Уязвимость системы управления базами данных PostgreSQL, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
RLSA-2026:28208
Important: postgresql:13 security update
GHSA-r6v6-v5r9-3ggh
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
ELSA-2026-28208
ELSA-2026-28208: postgresql:13 security update (IMPORTANT)
BDU:2026-07097
Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию
ROS-20260708-73-0082
Уязвимость postgresql16
ROS-20260708-73-0009
Уязвимость postgresql18-1c
ROS-20260708-73-0008
Уязвимость postgresql18
ROS-20260708-73-0007
Уязвимость postgresql17-1c
ROS-20260708-73-0006
Уязвимость postgresql17
ROS-20260708-73-0005
Уязвимость postgresql15-1c
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6473 Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparound | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-6473 Integer wraparound in multiple PostgreSQL server features allows an un ... | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.2 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreS ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
GHSA-8rqw-w7xq-566r Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
BDU:2026-07102 Уязвимость системы управления базами данных PostgreSQL, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.8 | 1% Низкий | 3 месяца назад | |
RLSA-2026:28208 Important: postgresql:13 security update | 1% Низкий | около 1 месяца назад | ||
GHSA-r6v6-v5r9-3ggh Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
ELSA-2026-28208 ELSA-2026-28208: postgresql:13 security update (IMPORTANT) | около 1 месяца назад | |||
BDU:2026-07097 Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
ROS-20260708-73-0082 Уязвимость postgresql16 | CVSS3: 8.8 | 1% Низкий | 23 дня назад | |
ROS-20260708-73-0009 Уязвимость postgresql18-1c | CVSS3: 8.8 | 1% Низкий | 23 дня назад | |
ROS-20260708-73-0008 Уязвимость postgresql18 | CVSS3: 8.8 | 1% Низкий | 23 дня назад | |
ROS-20260708-73-0007 Уязвимость postgresql17-1c | CVSS3: 8.8 | 1% Низкий | 23 дня назад | |
ROS-20260708-73-0006 Уязвимость postgresql17 | CVSS3: 8.8 | 1% Низкий | 23 дня назад | |
ROS-20260708-73-0005 Уязвимость postgresql15-1c | CVSS3: 8.8 | 1% Низкий | 23 дня назад |
Уязвимостей на страницу