Skip to main content

Threats Tagged 'cve-2026-63385'

View all threats tagged with 'cve-2026-63385'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-63385

Threats Tagged 'cve-2026-63385'

Click on any threat for detailed analysis and mitigation recommendations

Multiple vulnerabilities were identified in libevent versions prior to 2.1.13 and 2.2.2-a affecting various Ubuntu LTS releases from 14.04 through 26.04. These include use-after-free issues leading to denial of service or arbitrary code execution, HTTP request smuggling, out-of-bounds reads, resource exhaustion, and inconsistent HTTP message interpretation that could bypass security restrictions. Fixes have been released and are available through standard system updates or Ubuntu Pro for extended support versions.

Join the discussion

PostgreSQL is an advanced object-relational database management system (DBMS). Security Fix(es): * postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662) * postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464) * postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471) * postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680) * postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664) * postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677) * postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound (CVE-2026-15742) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle (CVE-2026-16239) * postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation (CVE-2026-14669) * postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation (CVE-2026-14679) * postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module (CVE-2026-14671) * postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow (CVE-2026-14670) * postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator (CVE-2026-14668) * postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists (CVE-2026-19385) * postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse (CVE-2026-15741) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Multiple security vulnerabilities have been identified in the libevent library used in Red Hat Hardened Images. These include denial of service, memory corruption, buffer overflow, request smuggling, arbitrary code execution, and access control bypass issues. The vulnerabilities affect specific stable versions of libevent and have been addressed in updated packages.

Join the discussion

Multiple security vulnerabilities were identified in libevent, an asynchronous event notification library, affecting various versions used in Red Hat and Ubuntu distributions. These include denial of service, HTTP request smuggling, buffer overflows, access control bypass, and arbitrary code execution issues. The vulnerabilities impact HTTP parsing, RPC data handling, and AF_UNIX socket processing. Fixes are available through official updates from Red Hat and Ubuntu, including Ubuntu Pro for extended support. Users are advised to apply the provided patches to mitigate these risks.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cve-2026-63385
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses