<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:23:32.049821+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:3714</id>
    <title>ALSA-2023:3714 — Moderate: postgresql security update</title>
    <updated>2026-10-03T06:23:32.199660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: postgresql, AlmaLinux:9: postgresql-contrib, AlmaLinux:9: postgresql-docs, AlmaLinux:9: postgresql-plperl, AlmaLinux:9: postgresql-plpython3, AlmaLinux:9: postgresql-pltcl, AlmaLinux:9: postgresql-private-devel, AlmaLinux:9: postgresql-private-libs, AlmaLinux:9: postgresql-server, AlmaLinux:9: postgresql-server-devel and 4 more</p>
<p>PostgreSQL is an advanced object-relational database management system (DBMS).</p>
<p>Security Fix(es):</p>
<p>* postgresql: schema_element defeats protective search_path changes (CVE-2023-2454)
* postgresql: row security policies disregard user ID changes after inlining. (CVE-2023-2455)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:3714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03247</id>
    <title>bdu:2023-03247</title>
    <updated>2026-10-03T06:23:32.199756+00:00</updated>
    <content>bdu:2023-03247</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-2454</id>
    <title>Withdrawn: BELL-CVE-2023-2454 — CVE-2023-2454 does not affect BellSoft software</title>
    <updated>2026-10-03T06:23:32.199780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-2454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgresql-2023-2454</id>
    <title>BIT-postgresql-2023-2454</title>
    <updated>2026-10-03T06:23:32.199795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgresql</p>
<p>schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgresql-2023-2454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0378</id>
    <title>certfr-2023-avi-0378 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles
permettent à un attaquant de provoquer une exécu…</title>
    <updated>2026-10-03T06:23:32.199815+00:00</updated>
    <content>certfr-2023-avi-0378</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0378"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bk83447</id>
    <title>CLEANSTART-2026-BK83447 — Security fix for CVE-2023-2454 applied in: postgresql15 15.3-r0</title>
    <updated>2026-10-03T06:23:32.199830+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: postgresql15</p>
<p>Security vulnerability affects the postgresql15 package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bk83447"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-242898</id>
    <title>EUVD-2026-242898</title>
    <updated>2026-10-03T06:23:32.199849+00:00</updated>
    <content>EUVD-2026-242898</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-242898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-2454</id>
    <title>fkie_cve-2023-2454</title>
    <updated>2026-10-03T06:23:32.199859+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-2454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9fff-w5w3-5x9g</id>
    <title>GHSA-9fff-w5w3-5x9g</title>
    <updated>2026-10-03T06:23:32.199879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9fff-w5w3-5x9g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-2454</id>
    <title>gsd-2023-2454</title>
    <updated>2026-10-03T06:23:32.199893+00:00</updated>
    <content>gsd-2023-2454</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-2454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-15</id>
    <title>ICSA-24-046-15 — Siemens SINEC NMS</title>
    <updated>2026-10-03T06:23:32.199903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a TLS server, this can be triggered if the server requests client authentication and a malicious client connects. A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-15"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1567</id>
    <title>OESA-2023-1567 — libpq security update</title>
    <updated>2026-10-03T06:23:32.200155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: libpq</p>
<p>PostgreSQL is a powerful, open source object-relational database system that uses and extends the SQL language combined with many features that safely store and scale the most complicated data workloads. This package provides the essential shared library for any PostgreSQL client program or interface.



Security Fix(es):

** DISPUTED ** An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).(CVE-2020-21469)

schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.(CVE-2023-2454)

Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifica…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12929-1</id>
    <title>openSUSE-SU-2024:12929-1 — postgresql11-11.20-1.1 on GA media</title>
    <updated>2026-10-03T06:23:32.200189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql11-11.20-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12929-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:4313</id>
    <title>RHSA-2023:4313 — Red Hat Security Advisory: rh-postgresql12-postgresql security update</title>
    <updated>2026-10-03T06:23:32.200207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: schema_element defeats protective search_path changes postgresql: row security policies disregard user ID changes after inlining.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:4313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2198-1</id>
    <title>SUSE-SU-2023:2198-1 — Security update for postgresql12</title>
    <updated>2026-10-03T06:23:32.200225+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql12</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2198-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2454</id>
    <title>UBUNTU-CVE-2023-2454</title>
    <updated>2026-10-03T06:23:32.200241+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14</p>
<p>schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-2454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1203</id>
    <title>WID-SEC-W-2023-1203 — PostgreSQL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T06:23:32.200264+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Programmcode auszuführen oder Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1203"/>
  </entry>
</feed>
