Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 64

Количество 64

github логотип

GHSA-9625-p7pg-3cxg

больше 2 лет назад

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-7790

больше 2 лет назад

ELSA-2023-7790: postgresql:10 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-7783

больше 2 лет назад

ELSA-2023-7783: postgresql security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2023-07840

больше 2 лет назад

Уязвимость функций array_append, array_prepend, array_subscript_handler системы управления базами данных PostgreSQL, связанная с целочисленным переполнением при модификации массивов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9625-p7pg-3cxg

A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.

CVSS3: 8.8
4%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2023-7790

ELSA-2023-7790: postgresql:10 security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-7783

ELSA-2023-7783: postgresql security update (IMPORTANT)

больше 2 лет назад
fstec логотип
BDU:2023-07840

Уязвимость функций array_append, array_prepend, array_subscript_handler системы управления базами данных PostgreSQL, связанная с целочисленным переполнением при модификации массивов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
4%
Низкий
больше 2 лет назад

Уязвимостей на страницу