Search CVE reports
951 – 960 of 55618 results
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the...
7 affected packages
postgresql-18, postgresql-16, postgresql-14, postgresql-12, postgresql-10...
| Package | 16.04 LTS |
|---|---|
| postgresql-18 | — |
| postgresql-16 | — |
| postgresql-14 | — |
| postgresql-12 | — |
| postgresql-10 | — |
| postgresql-9.5 | Needs evaluation |
| postgresql-9.3 | — |