Количество 108
Количество 108
BDU:2026-07100
Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы
ROS-20260707-73-0058
Уязвимость postgresql16
ROS-20260706-73-0031
Уязвимость postgresql18-1c
ROS-20260706-73-0030
Уязвимость postgresql18
ROS-20260706-73-0029
Уязвимость postgresql17-1c
ROS-20260706-73-0028
Уязвимость postgresql17
ROS-20260706-73-0027
Уязвимость postgresql15-1c
ROS-20260706-73-0026
Уязвимость postgresql15
ROS-20260706-73-0025
Уязвимость postgresql14
ROS-20260706-73-0024
Уязвимость postgresql-1c
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6477
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6477
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6478
PostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-6478
Covert timing channel in comparison of MD5-hashed password in PostgreS ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07100 Уязвимость утилит pg_basebackup и pg_rewind системы управления базами данных PostgreSQL, позволяющая нарушителю перезаписывать произвольные файлы | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0058 Уязвимость postgresql16 | CVSS3: 8.8 | 0% Низкий | 24 дня назад | |
ROS-20260706-73-0031 Уязвимость postgresql18-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0030 Уязвимость postgresql18 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0029 Уязвимость postgresql17-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0028 Уязвимость postgresql17 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0027 Уязвимость postgresql15-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0026 Уязвимость postgresql15 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0025 Уязвимость postgresql14 | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0024 Уязвимость postgresql-1c | CVSS3: 8.8 | 0% Низкий | 25 дней назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6477 PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-6477 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ... | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.2 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 PostgreSQL discloses MD5-hashed passwords via covert timing channel | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-6478 Covert timing channel in comparison of MD5-hashed password in PostgreS ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу