<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:37:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-03335</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-03335</link>
      <description>bdu:2019-03335</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-03335</guid>
    </item>
    <item>
      <title>cnvd-2017-36407</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-36407</link>
      <description>cnvd-2017-36407</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-36407</guid>
    </item>
    <item>
      <title>EUVD-2026-173922</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-173922</link>
      <description>EUVD-2026-173922</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-173922</guid>
    </item>
    <item>
      <title>fkie_cve-2017-12172</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-12172</link>
      <description>&lt;p&gt;PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. PostgreSQL provides a script for starting the database server during system boot. Packages of PostgreSQL for many operating systems provide their own, packager-authored startup implementations. Several implementations use a log file name that the database superuser can replace with a symbolic link. As root, they open(), chmod() and/or chown() this log file name. This often suffices for the database superuser to escalate to root privileges when root starts the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. PostgreSQL provides a script for starting the database server during system boot. Packages of PostgreSQL for many operating systems provide their own, packager-authored startup implementations. Several implementations use a log file name that the database superuser can replace with a symbolic link. As root, they open(), chmod() and/or chown() this log file name. This often suffices for the database superuser to escalate to root privileges when root starts the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-12172</guid>
    </item>
    <item>
      <title>GHSA-r936-w9vp-c53q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-r936-w9vp-c53q</link>
      <description>&lt;p&gt;PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. PostgreSQL provides a script for starting the database server during system boot. Packages of PostgreSQL for many operating systems provide their own, packager-authored startup implementations. Several implementations use a log file name that the database superuser can replace with a symbolic link. As root, they open(), chmod() and/or chown() this log file name. This often suffices for the database superuser to escalate to root privileges when root starts the server.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. PostgreSQL provides a script for starting the database server during system boot. Packages of PostgreSQL for many operating systems provide their own, packager-authored startup implementations. Several implementations use a log file name that the database superuser can replace with a symbolic link. As root, they open(), chmod() and/or chown() this log file name. This often suffices for the database superuser to escalate to root privileges when root starts the server.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-r936-w9vp-c53q</guid>
    </item>
    <item>
      <title>gsd-2017-12172</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-12172</link>
      <description>gsd-2017-12172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-12172</guid>
    </item>
    <item>
      <title>RHSA-2017:3402 — Red Hat Security Advisory: postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:3402</link>
      <description>&lt;p&gt;postgresql: Start scripts permit database administrator to modify root-owned files postgresql: Start scripts permit database administrator to modify root-owned files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: Start scripts permit database administrator to modify root-owned files postgresql: Start scripts permit database administrator to modify root-owned files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:3402</guid>
    </item>
    <item>
      <title>RHSA-2017:3403 — Red Hat Security Advisory: rh-postgresql94-postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2017:3403</link>
      <description>&lt;p&gt;postgresql: Start scripts permit database administrator to modify root-owned files postgresql: Start scripts permit database administrator to modify root-owned files&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: Start scripts permit database administrator to modify root-owned files postgresql: Start scripts permit database administrator to modify root-owned files&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2017:3403</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:0077-1 — Security update for postgresql94</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:0077-1</link>
      <description>&lt;p&gt;Security update for postgresql94&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql94&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:0077-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0143 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0143</link>
      <description>&lt;p&gt;Ein lokaler oder entfernter authenitisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Daten einzusehen, Daten zu manipulieren, einen Denial of Serivce auszulösen oder Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder entfernter authenitisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Daten einzusehen, Daten zu manipulieren, einen Denial of Serivce auszulösen oder Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0143</guid>
    </item>
  </channel>
</rss>
