<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:30:40.362966+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-04232</id>
    <title>bdu:2019-04232</title>
    <updated>2026-10-03T08:30:40.377789+00:00</updated>
    <content>bdu:2019-04232</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-04232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2018-1053</id>
    <title>Withdrawn: BELL-CVE-2018-1053 — CVE-2018-1053 does not affect BellSoft software</title>
    <updated>2026-10-03T08:30:40.377832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2018-1053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-sx71048</id>
    <title>Withdrawn: CLEANSTART-2026-SX71048 — Security fixes in postgresql 10.2-r0</title>
    <updated>2026-10-03T08:30:40.377852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: postgresql</p>
<p>Package postgresql version 10.2-r0 fixes 2 vulnerabilities: CVE-2018-1052, CVE-2018-1053</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-sx71048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-05754</id>
    <title>cnvd-2018-05754</title>
    <updated>2026-10-03T08:30:40.377880+00:00</updated>
    <content>cnvd-2018-05754</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-05754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-185561</id>
    <title>EUVD-2026-185561</title>
    <updated>2026-10-03T08:30:40.377894+00:00</updated>
    <content>EUVD-2026-185561</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-185561"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1053</id>
    <title>fkie_cve-2018-1053</title>
    <updated>2026-10-03T08:30:40.377905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2018-1053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h73g-3m4r-j2cr</id>
    <title>GHSA-h73g-3m4r-j2cr</title>
    <updated>2026-10-03T08:30:40.377929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h73g-3m4r-j2cr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2018-1053</id>
    <title>gsd-2018-1053</title>
    <updated>2026-10-03T08:30:40.377946+00:00</updated>
    <content>gsd-2018-1053</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2018-1053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1</id>
    <title>openSUSE-SU-2024:11184-1 — postgresql10-10.18-1.3 on GA media</title>
    <updated>2026-10-03T08:30:40.377956+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql10-10.18-1.3 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2018:2511</id>
    <title>RHSA-2018:2511 — Red Hat Security Advisory: rh-postgresql95-postgresql security update</title>
    <updated>2026-10-03T08:30:40.377979+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2018:2511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0506-1</id>
    <title>SUSE-SU-2018:0506-1 — Security update for postgresql94</title>
    <updated>2026-10-03T08:30:40.378002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql94</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0506-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1053</id>
    <title>UBUNTU-CVE-2018-1053</title>
    <updated>2026-10-03T08:30:40.378016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: postgresql-9.3, Ubuntu:16.04:LTS: postgresql-9.5</p>
<p>In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1053"/>
  </entry>
</feed>
