CVEs (137)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 17, 2026 Dec 10, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation re...Show more |
2Postgresql Redhat21Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+18 moreJun 17, 2026 Dec 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during a...Show more |
2Postgresql Redhat16Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little Endian EusCodeready Linux Builder For Arm64 Eus+13 moreJun 23, 2026 Dec 10, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type val...Show more |
2Php Redhat3Enterprise Linux PhpSoftware CollectionsJun 17, 2026 Nov 2, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. |
3Debian PostgresqlRedhat4Debian Linux Enterprise LinuxPostgresql+1 moreJun 17, 2026 Aug 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has instal...Show more |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Jun 9, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role...Show more |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Jun 9, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code. |
3Fedoraproject HaproxyRedhat9Ceph Storage Extra Packages For Enterprise LinuxFedora+6 moreJun 17, 2026 Mar 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenSh...Show more |
3C Ares Project FedoraprojectRedhat4C Ares Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 6, 2023 N/A· v4 8.6 HIGH· v3 N/A· v2 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or...Show more |
3Fedoraproject PythonRedhat5Enterprise Linux FedoraPython+2 moreJun 17, 2026 Sep 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (fl...Show more |
4Debian NetappPython+1 more5Debian Linux Enterprise LinuxOntap Select Deploy Administration Utility+2 moreJun 17, 2026 Aug 24, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an a...Show more |
3Fedoraproject LinuxRedhat263scale Api Management Codeready Linux BuilderEnterprise Linux+23 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
3Fedoraproject PostgresqlRedhat6Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+3 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established,...Show more |
3Fedoraproject PostgresqlRedhat7Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+4 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not requi...Show more |
3Debian HaproxyRedhat5Debian Linux Enterprise LinuxHaproxy+2 moreJun 17, 2026 Mar 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulti...Show more |
6Debian FedoraprojectOpensuse+3 more9Cgi Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby. |
6Debian FedoraprojectOpensuse+3 more9Date Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
6Debian FedoraprojectNetapp+3 more8Communications Operations Monitor Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Oct 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. Thi...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |