Skip to content
← All tracked CVEs

Updated 05:00

Medium severity

Medium45d SLA

Our service-level agreement (SLA) gives a medium vulnerability a fix within 45 days of publication. 446 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
OpenPostgreSQL: Stale RLS from role/ownership changes enables unauthorized reads/writes via plan reusesecure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPostgreSQL pgcrypto disabled-cipher bug allows cleartext recovery; wrong-key decrypt bypasses MDCsecure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24secure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPostgreSQL pg_trgm picksplit buffer over-read leaks memory via split choices; pre-18.5/17.11/16.15/15.19/14.24secure-packages-rollingAug 24, 2026Oct 8, 2026
OpenAttacker-controlled CR in configparser multiline values injects unexpected configuration keys and valuessecure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPrivilege check bypass in PostgreSQL DDL enables DoS via type dependencies (pre-18.5/17.11/16.15/15.19/14.24)secure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPostgreSQL 16–18 SCRAM iteration-count leak allows unauthenticated user enumeration when non-default scram_iterationssecure-packages-rollingAug 24, 2026Oct 8, 2026
OpenPostgreSQL ascii() buffer over-read leaks up to 3 bytes; affects versions before 18.5/17.11/16.15/15.19/14.24secure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL RLS cache invalidation bug allows unauthorized access after role/ownership changes via plan reusesecure-packages-26.05Aug 25, 2026Oct 9, 2026
Openconfigparser CR in multiline values allows injected keys/values via attacker-controlled inputsecure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL 16–18: SCRAM iteration-count discrepancy enables unauthenticated user enumerationsecure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL pgcrypto disabled OpenSSL ciphers leak plaintext; wrong-key decryption bypasses MDCsecure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL pg_trgm picksplit heap buffer over-read may leak memory via split choicessecure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL DDL lacks auth for range subtype/expressions, enabling DoS on type ALTER/DROPsecure-packages-26.05Aug 25, 2026Oct 9, 2026
OpenPostgreSQL stale RLS policies after role or ownership changes due to plan reusesecure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenPostgreSQL ascii() buffer over-read leaks up to 3 bytes via crafted text; affects <18.5/17.11/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenPostgreSQL pgcrypto vuln: disabled ciphers allow cleartext recovery, wrong-key decryption bypasses MDCsecure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenSCRAM auth iteration-count discrepancy enables user enumeration with non-default scram_iterations; affects PostgreSQL 16–18 pre 18.5/17.11/16.15secure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenConfigParser write() allows key/value injection via CR in attacker-controlled multiline valuessecure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenPostgreSQL pg_trgm picksplit buffer over-read enabling memory inference; affects pre-18.5/17.11/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Oct 9, 2026
OpenPostgreSQL DDL missing auth enables DoS on type ALTER/DROP via range/expression dependenciessecure-packages-25.11Aug 25, 2026Oct 9, 2026
Fixed within SLAHDF5 h5repack double free on crafted file with oversized chunk sizesecure-packages-25.11Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAHDF5 <=2.1.1 SOHM list-index deserialization heap overflow via crafted file, causing crashsecure-packages-25.11Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAHDF5 NULL pointer dereference on reading attribute with invalid variable-length datatype fieldsecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAHDF5 h5repack double free when parsing oversized chunk size in crafted filesecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLAHeap-based buffer overflow in HDF5 <=2.1.1 SOHM list-index deserialization (DoS)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 26, 20261 day
Fixed within SLANULL pointer dereference when reading crafted HDF5 attribute with invalid variable-length datatypesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLADouble free vulnerability in HDF5 h5repack triggered by crafted file oversized chunk sizesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAHeap overflow in HDF5 SOHM list-index deserialization triggers DoS with crafted file through 2.1.1secure-packages-rollingAug 24, 2026Oct 8, 2026Aug 26, 20261 day
Fixed within SLAHigh-severity Skia info leak in Chrome <151.0.7922.169 enables origin policy bypass via crafted HTML pagesecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAChrome Android Core reference resolution bug leaks sensitive data via crafted HTML pre-151.0.7922.169secure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAChrome <151.0.7922.169 CORS flaw enables compromised renderer to bypass site isolation via crafted HTMLsecure-packages-rollingAug 24, 2026Oct 8, 2026Aug 25, 20261 day
Fixed within SLAHigh-severity Skia info leak in Chrome <151.0.7922.169 allows origin policy bypass via crafted HTMLsecure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLAChrome Android Core reference resolution bug leaks sensitive data via crafted HTML (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLACORS implementation flaw lets compromised renderer bypass Chrome site isolation (pre-151.0.7922.169)secure-packages-26.05Aug 25, 2026Oct 9, 2026Aug 25, 2026same day
Fixed within SLANetfs zero_point misupdated with i_size > remote_i_size, causing short reads on EOFsecure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAdrm/msm/adreno: missing of_node_put causes node reference leak in a6xx_gpu_init()secure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAEROFS xattr inode init leaks folio reference when metabuf not dropped on errorssecure-packages-rollingAug 18, 2026Oct 2, 2026Aug 25, 20266 days
Fixed within SLAGStreamer gst-plugins-good avidemux vprp parser OOB read via crafted AVI causes DoSsecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAHeap OOB read/write and leak via FUJIFILM strd underflow in GStreamer avidemuxsecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAnetfs_release_folio zero_point misupdate when i_size > remote_i_size causes short readssecure-packages-26.05Aug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAReference leak in drm/msm/adreno a6xx_gpu_init from of_parse_phandle early-return pathssecure-packages-26.05Aug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAERoFS inode xattr init: metabuf/folio ref leak on error paths after erofs_read_metabufsecure-packages-26.05Aug 19, 2026Oct 3, 2026Aug 19, 2026same day
Fixed within SLAnetfs_release_folio zero_point update uses i_size not remote_i_size, causing EOF short readssecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAReference leak in a6xx_gpu_init() due to missed of_node_put on early error pathssecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAERoFS inode xattr init error paths leak metabuf, causing folio reference leaksecure-packages-25.11Aug 18, 2026Oct 2, 2026Aug 19, 20261 day
Fixed within SLAArithmetic overflow in af_alg AEAD AD length leads to TX buffer size miscalculationsecure-packages-25.11Jul 16, 2026Aug 30, 2026Aug 17, 202632 days
Fixed within SLAsecure-packages-25.11Jul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAsecure-packages-25.11Jul 8, 2026Aug 22, 2026Aug 17, 202640 days
Fixed within SLAsecure-packages-25.11Jul 8, 2026Aug 22, 2026Aug 17, 202640 days