Количество 24 659
Количество 24 659
CVE-2026-6637
PostgreSQL refint allows stack buffer overflow and SQL injection
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66035
libssh2 Heap Buffer Overflow via ETM Cipher Negotiation
CVE-2026-66034
libssh2 Heap Out-of-Bounds Read via publickey subsystem
CVE-2026-66033
libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
CVE-2026-66032
libssh2 Double-Free Heap Corruption via sftp_open()
CVE-2026-6507
Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing
CVE-2026-6479
PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
CVE-2026-6478
PostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-6477
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6475
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVE-2026-6474
PostgreSQL timeofday() can disclose portions of server memory
CVE-2026-6473
PostgreSQL server undersizes allocations, via integer wraparound
CVE-2026-6472
PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
CVE-2026-64600
xfs: resample the data fork mapping after cycling ILOCK
CVE-2026-64530
net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
CVE-2026-64529
crypto: qat - remove unused character device and IOCTLs
CVE-2026-64525
xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVE-2026-64523
net/handshake: Take a long-lived file reference at submit
CVE-2026-64514
userfaultfd: gate must_wait writability check on pte_present()
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | 0% Низкий | 6 дней назад | ||
CVE-2026-66035 libssh2 Heap Buffer Overflow via ETM Cipher Negotiation | 0% Низкий | 6 дней назад | ||
CVE-2026-66034 libssh2 Heap Out-of-Bounds Read via publickey subsystem | 0% Низкий | 6 дней назад | ||
CVE-2026-66033 libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation | 0% Низкий | 6 дней назад | ||
CVE-2026-66032 libssh2 Double-Free Heap Corruption via sftp_open() | 0% Низкий | 6 дней назад | ||
CVE-2026-6507 Dnsmasq: dnsmasq: denial of service due to out-of-bounds write in dhcp bootreply processing | 0% Низкий | 3 месяца назад | ||
CVE-2026-6479 PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-6475 PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6474 PostgreSQL timeofday() can disclose portions of server memory | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-6473 PostgreSQL server undersizes allocations, via integer wraparound | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
CVE-2026-6472 PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK | 0% Низкий | 8 дней назад | ||
CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle | 1% Низкий | 5 дней назад | ||
CVE-2026-64529 crypto: qat - remove unused character device and IOCTLs | 0% Низкий | 6 дней назад | ||
CVE-2026-64525 xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit | 0% Низкий | 6 дней назад | ||
CVE-2026-64523 net/handshake: Take a long-lived file reference at submit | 0% Низкий | 6 дней назад | ||
CVE-2026-64514 userfaultfd: gate must_wait writability check on pte_present() | 0% Низкий | 6 дней назад |
Уязвимостей на страницу