Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 149

Количество 149

redos логотип

ROS-20260706-80-0028

2 месяца назад

Уязвимость postgresql15

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0027

2 месяца назад

Уязвимость postgresql-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-80-0026

2 месяца назад

Уязвимость postgresql

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0031

2 месяца назад

Уязвимость postgresql18-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0030

2 месяца назад

Уязвимость postgresql18

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0029

2 месяца назад

Уязвимость postgresql17-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0028

2 месяца назад

Уязвимость postgresql17

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0027

2 месяца назад

Уязвимость postgresql15-1c

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0026

2 месяца назад

Уязвимость postgresql15

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0025

2 месяца назад

Уязвимость postgresql14

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20260706-73-0024

2 месяца назад

Уязвимость postgresql-1c

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6477

4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2026-6477

4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2026-6477

4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
EPSS: Низкий
msrc логотип

CVE-2026-6477

4 месяца назад

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-6477

4 месяца назад

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
EPSS: Низкий
nvd логотип

CVE-2026-6478

4 месяца назад

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2026-6478

4 месяца назад

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20260706-80-0028

Уязвимость postgresql15

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0027

Уязвимость postgresql-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-80-0026

Уязвимость postgresql

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0031

Уязвимость postgresql18-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0030

Уязвимость postgresql18

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0029

Уязвимость postgresql17-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0028

Уязвимость postgresql17

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0027

Уязвимость postgresql15-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0026

Уязвимость postgresql15

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0025

Уязвимость postgresql14

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260706-73-0024

Уязвимость postgresql-1c

CVSS3: 8.8
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-6477

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6477

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6477

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.8
0%
Низкий
4 месяца назад
msrc логотип
CVE-2026-6477

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory

CVSS3: 8.8
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-6477

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ...

CVSS3: 8.8
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 8.2
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-6478

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS3: 6.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-6478

PostgreSQL discloses MD5-hashed passwords via covert timing channel

CVSS3: 6.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу