| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Low
|
CVE-2026-6638
- PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6637
- PostgreSQL refint allows stack buffer overflow and SQL injection
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2026-6575
- PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6479
- PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2026-6478
- PostgreSQL discloses MD5-hashed passwords via covert timing channel
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6477
- PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6476
- PostgreSQL pg_createsubscriber allows SQL injection via subscription name
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6475
- PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2026-6474
- PostgreSQL timeofday() can disclose portions of server memory
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-6473
- PostgreSQL server undersizes allocations, via integer wraparound
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2026-6472
- PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
|
5/14/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-2007
- PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
|
2/12/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-2006
- PostgreSQL missing validation of multibyte character length executes arbitrary code
|
2/12/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-2005
- PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
|
2/12/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2026-2004
- PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
|
2/12/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2026-2003
- PostgreSQL oidvector discloses a few bytes of memory
|
2/12/2026 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2024-7348
- PostgreSQL relation replacement during pg_dump executes arbitrary SQL
|
8/8/2024 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Low
|
CVE-2024-4317
- PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checks
|
5/9/2024 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
High
|
CVE-2024-10979
- PostgreSQL PL/Perl environment variable changes execute arbitrary code
|
11/14/2024 |
| mingw64-x86_64-postgresql |
conf-mingw-w64-postgresql-x86_64.1
|
n/a
|
Medium
|
CVE-2024-10978
- PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID
|
11/14/2024 |