Количество 21
Количество 21
GHSA-96xx-m79q-xh44
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6637
PostgreSQL refint allows stack buffer overflow and SQL injection
CVE-2026-6637
Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ...
BDU:2026-07094
Уязвимость модуля refint системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2026:2117-1
Security update for postgresql14
SUSE-SU-2026:2086-1
Security update for postgresql14
SUSE-SU-2026:2085-1
Security update for postgresql15
SUSE-SU-2026:2007-1
Security update for postgresql14
SUSE-SU-2026:2000-1
Security update for postgresql15
SUSE-SU-2026:1999-1
Security update for postgresql15
SUSE-SU-2026:2084-1
Security update for postgresql16
SUSE-SU-2026:2001-1
Security update for postgresql16
SUSE-SU-2026:1942-1
Security update for postgresql16
SUSE-SU-2026:2303-1
Security update for postgresql17
SUSE-SU-2026:1943-1
Security update for postgresql17
openSUSE-SU-2026:20901-1
Security update for postgresql18
SUSE-SU-2026:1946-1
Security update for postgresql18
SUSE-SU-2026:1945-1
Security update for postgresql18
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-96xx-m79q-xh44 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 PostgreSQL refint allows stack buffer overflow and SQL injection | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ... | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
BDU:2026-07094 Уязвимость модуля refint системы управления базами данных PostgreSQL, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:2117-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2086-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2085-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:2007-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2000-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:1999-1 Security update for postgresql15 | 2 месяца назад | |||
SUSE-SU-2026:2084-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:2001-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:1942-1 Security update for postgresql16 | 2 месяца назад | |||
SUSE-SU-2026:2303-1 Security update for postgresql17 | около 2 месяцев назад | |||
SUSE-SU-2026:1943-1 Security update for postgresql17 | 2 месяца назад | |||
openSUSE-SU-2026:20901-1 Security update for postgresql18 | около 2 месяцев назад | |||
SUSE-SU-2026:1946-1 Security update for postgresql18 | 2 месяца назад | |||
SUSE-SU-2026:1945-1 Security update for postgresql18 | 2 месяца назад |
Уязвимостей на страницу