Collected every two hours from specialised publications — each link leads to the original article.
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation. (CVE-2025-4207) References: - https://bugs.mage…
new module: postgresql:16
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the Mari…
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation. (CVE-2025-1094) References: - https://bugs.mageia.org/show_bug…
A security issue was discovered in the PostgreSQL database system. Under certain usage patterns, improper neutralization of quoting syntax could make it possib…
Redis' Lua library commands may lead to remote code execution. (CVE-2024-46981) Redis allows denial-of-service due to malformed ACL selectors. (CVE-2024-51741)
Two security issues were discovered in Redis, a persistent key-value database, which could result in the execution of arbitrary code or denial of service.
Redis 7.2.7 Released Mon 6 Jan 2025 12:30:00 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes (CVE-2024-46981) Lua script commands may le…
Important: postgresql:15 security update
Important: postgresql:16 security update
Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.
Several security issues were fixed in PostgreSQL.
Multiple vulnerabilities have been fixed in the key¢''value database Redis. CVE-2022-35977
Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debi…
Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For the …
Several security issues were fixed in MySQL.
PostgreSQL could execute arbitrary SQL functions as the superuser if it received a specially crafted SQL object.
Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes CVE-2024-31449 Lua libra…
PostgreSQL could execute arbitrary SQL functions as the superuser if it received a specially crafted SQL object.
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute sh…
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_d…
It was discovered that there were a number of issues in Redis, a popular key-value database: * CVE-2023-45145: On startup, Redis began listening on a Unix
MySQL 8.0.39 Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html
MySQL 8.0.39 Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-38.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-39.html