Threats Tagged 'cve-2026-6477'
View all threats tagged with 'cve-2026-6477'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-6477'
Click on any threat for detailed analysis and mitigation recommendations
Security update for postgresql17CVE-2026-6472 0 This security update for postgresql17 addresses multiple vulnerabilities by updating to version 17. 10. The fixes include privilege checks, integer overflow prevention, protection against malicious time zone names, path traversal prevention, proper quoting of subscription and object names, marking unsafe functions, timing-safe string comparisons, recursion limits, and prevention of SQL injection and buffer overruns. Non-security improvements related to system updates are also included. Join the discussion | GCVE Database | 06/08/2026, 15:27:50 UTC Added: 05/31/2026, 21:00:26 UTC |
CVE-2026-6477: Use of Inherently Dangerous Function in PostgreSQLCVE-2026-6477 0 CVE-2026-6477 is a high-severity vulnerability in PostgreSQL affecting versions before 18. 4, 17. 10, 16. 14, 15. 18, and 14. 23. It involves the use of an inherently dangerous function PQfn in libpq functions lo_export(), lo_read(), lo_lseek64(), and lo_tell64(), which allows the server superuser to overwrite a client stack buffer with arbitrarily large data. This vulnerability can lead to memory corruption in client tools such as psql and pg_dump that invoke these functions. The flaw arises because PQfn stores server-determined data of arbitrary length into a buffer without size constraints, similar to the unsafe gets() function. No official patch or remediation level is currently provided in the available data. Join the discussion | CVE Database V5 | 05/14/2026, 13:00:12 UTC Added: 05/14/2026, 13:36:40 UTC |
Showing 1 to 2 of 2 results