Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 72

Количество 72

nvd логотип

CVE-2026-6473

3 месяца назад

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-6473

2 месяца назад

PostgreSQL server undersizes allocations, via integer wraparound

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-6473

3 месяца назад

Integer wraparound in multiple PostgreSQL server features allows an un ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6478

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6478

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-6478

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-6478

3 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-6478

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreS ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8rqw-w7xq-566r

3 месяца назад

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-07102

3 месяца назад

Уязвимость системы управления базами данных PostgreSQL, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2026:28208

около 1 месяца назад

Important: postgresql:13 security update

EPSS: Низкий
github логотип

GHSA-r6v6-v5r9-3ggh

3 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-28208

около 1 месяца назад

ELSA-2026-28208: postgresql:13 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-07097

3 месяца назад

Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20260708-73-0082

23 дня назад

Уязвимость postgresql16

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0009

23 дня назад

Уязвимость postgresql18-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0008

23 дня назад

Уязвимость postgresql18

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0007

23 дня назад

Уязвимость postgresql17-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0006

23 дня назад

Уязвимость postgresql17

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260708-73-0005

23 дня назад

Уязвимость postgresql15-1c

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-6473

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6473

PostgreSQL server undersizes allocations, via integer wraparound

CVSS3: 8.8
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-6473

Integer wraparound in multiple PostgreSQL server features allows an un ...

CVSS3: 8.8
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6478

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreS ...

CVSS3: 6.5
1%
Низкий
3 месяца назад
github логотип
GHSA-8rqw-w7xq-566r

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
1%
Низкий
3 месяца назад
fstec логотип
BDU:2026-07102

Уязвимость системы управления базами данных PostgreSQL, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.8
1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:28208

Important: postgresql:13 security update

1%
Низкий
около 1 месяца назад
github логотип
GHSA-r6v6-v5r9-3ggh

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-28208

ELSA-2026-28208: postgresql:13 security update (IMPORTANT)

около 1 месяца назад
fstec логотип
BDU:2026-07097

Уязвимость системы управления базами данных PostgreSQL, связанная с раскрытием информации на основании временных расхождений, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260708-73-0082

Уязвимость postgresql16

CVSS3: 8.8
1%
Низкий
23 дня назад
redos логотип
ROS-20260708-73-0009

Уязвимость postgresql18-1c

CVSS3: 8.8
1%
Низкий
23 дня назад
redos логотип
ROS-20260708-73-0008

Уязвимость postgresql18

CVSS3: 8.8
1%
Низкий
23 дня назад
redos логотип
ROS-20260708-73-0007

Уязвимость postgresql17-1c

CVSS3: 8.8
1%
Низкий
23 дня назад
redos логотип
ROS-20260708-73-0006

Уязвимость postgresql17

CVSS3: 8.8
1%
Низкий
23 дня назад
redos логотип
ROS-20260708-73-0005

Уязвимость postgresql15-1c

CVSS3: 8.8
1%
Низкий
23 дня назад

Уязвимостей на страницу