Количество 1 300
Количество 1 300
RLSA-2026:44308
Important: libpq security update
RLSA-2026:28208
Important: postgresql:13 security update
RLSA-2024:6018
Important: postgresql:13 security update
RLSA-2024:6000
Important: postgresql:12 security update
RLSA-2024:5999
Important: postgresql security update
RLSA-2024:0975
Important: postgresql:13 security update
RLSA-2024:0974
Important: postgresql:12 security update
RLSA-2024:0973
Important: postgresql:15 security update
RLSA-2024:0956
Important: postgresql:10 security update
RLSA-2024:0951
Important: postgresql security update
RLSA-2024:0950
Important: postgresql:15 security update
RLSA-2023:0113
Moderate: postgresql:10 security update
RLSA-2022:7128
Moderate: postgresql:12 security update
RLSA-2022:4855
Important: postgresql:13 security update
RLSA-2022:4807
Important: postgresql:12 security update
RLSA-2022:4805
Important: postgresql:10 security update
RLSA-2022:4771
Important: postgresql security update
RLSA-2022:1891
Low: libpq security update
GHSA-xxfm-85xf-vx5m
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
GHSA-xvhg-pwg9-qp4r
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:44308 Important: libpq security update | 0% Низкий | около 2 месяцев назад | ||
RLSA-2026:28208 Important: postgresql:13 security update | 1% Низкий | 3 месяца назад | ||
RLSA-2024:6018 Important: postgresql:13 security update | 2% Низкий | больше 1 года назад | ||
RLSA-2024:6000 Important: postgresql:12 security update | 2% Низкий | почти 2 года назад | ||
RLSA-2024:5999 Important: postgresql security update | 2% Низкий | почти 2 года назад | ||
RLSA-2024:0975 Important: postgresql:13 security update | 2% Низкий | больше 2 лет назад | ||
RLSA-2024:0974 Important: postgresql:12 security update | 2% Низкий | около 1 года назад | ||
RLSA-2024:0973 Important: postgresql:15 security update | 2% Низкий | больше 2 лет назад | ||
RLSA-2024:0956 Important: postgresql:10 security update | 2% Низкий | больше 2 лет назад | ||
RLSA-2024:0951 Important: postgresql security update | 2% Низкий | больше 2 лет назад | ||
RLSA-2024:0950 Important: postgresql:15 security update | 2% Низкий | больше 2 лет назад | ||
RLSA-2023:0113 Moderate: postgresql:10 security update | 2% Низкий | больше 3 лет назад | ||
RLSA-2022:7128 Moderate: postgresql:12 security update | 2% Низкий | почти 4 года назад | ||
RLSA-2022:4855 Important: postgresql:13 security update | 16% Средний | больше 4 лет назад | ||
RLSA-2022:4807 Important: postgresql:12 security update | 16% Средний | больше 4 лет назад | ||
RLSA-2022:4805 Important: postgresql:10 security update | 16% Средний | больше 4 лет назад | ||
RLSA-2022:4771 Important: postgresql security update | 16% Средний | больше 4 лет назад | ||
RLSA-2022:1891 Low: libpq security update | 2% Низкий | больше 4 лет назад | ||
GHSA-xxfm-85xf-vx5m Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-xvhg-pwg9-qp4r PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while reading a protocol message, which allows remote attackers to conduct SQL injection attacks via crafted binary data in a parameter and causing an error, which triggers the loss of synchronization and part of the protocol message to be treated as a new message, as demonstrated by causing a timeout or query cancellation. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад |
Уязвимостей на страницу