<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:28:11 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-04099</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04099</link>
      <description>bdu:2019-04099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04099</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2017-15099 — CVE-2017-15099 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2017-15099</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2017-15099</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-FW42039 — vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row secur…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-fw42039</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the postgresql package. A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the postgresql package. A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-fw42039</guid>
    </item>
    <item>
      <title>cnvd-2017-36406</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2017-36406</link>
      <description>cnvd-2017-36406</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2017-36406</guid>
    </item>
    <item>
      <title>EUVD-2026-164535</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-164535</link>
      <description>EUVD-2026-164535</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-164535</guid>
    </item>
    <item>
      <title>fkie_cve-2017-15099</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2017-15099</link>
      <description>&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2017-15099</guid>
    </item>
    <item>
      <title>GHSA-pcph-v7q2-77cx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pcph-v7q2-77cx</link>
      <description>&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pcph-v7q2-77cx</guid>
    </item>
    <item>
      <title>gsd-2017-15099</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2017-15099</link>
      <description>gsd-2017-15099</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2017-15099</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11184-1 — postgresql10-10.18-1.3 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1</link>
      <description>&lt;p&gt;postgresql10-10.18-1.3 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql10-10.18-1.3 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11184-1</guid>
    </item>
    <item>
      <title>RHSA-2018:2511 — Red Hat Security Advisory: rh-postgresql95-postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:2511</link>
      <description>&lt;p&gt;postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: Memory disclosure in JSON functions postgresql: INSERT ... ON CONFLICT DO UPDATE fails to enforce SELECT privileges postgresql: pg_upgrade creates file of sensitive metadata under prevailing umask postgresql: Uncontrolled search path element in pg_dump and other client applications postgresql: Certain host connection parameters defeat client-side security defenses postgresql: Missing authorization and memory disclosure in INSERT ... ON CONFLICT DO UPDATE statements&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:2511</guid>
    </item>
    <item>
      <title>SUSE-SU-2017:3391-1 — Security update for postgresql96</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2017:3391-1</link>
      <description>&lt;p&gt;Security update for postgresql96&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql96&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2017:3391-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2017-15099</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-15099</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: postgresql-9.5&lt;/p&gt;
&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: postgresql-9.5&lt;/p&gt;
&lt;p&gt;INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-15099</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0143 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0143</link>
      <description>&lt;p&gt;Ein lokaler oder entfernter authenitisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Daten einzusehen, Daten zu manipulieren, einen Denial of Serivce auszulösen oder Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder entfernter authenitisierter Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um seine Privilegien zu erhöhen, vertrauliche Daten einzusehen, Daten zu manipulieren, einen Denial of Serivce auszulösen oder Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0143</guid>
    </item>
  </channel>
</rss>
