Collected every two hours from specialised publications — each link leads to the original article.
Two issues were discovered in Redis, the key-value database: * CVE-2025-32023: An authenticated user may have used a specially-crafted string to trigger a stac…
MariaDB Server 10.4 through 10.5.*, 10.6 through 10.6.*, 10.7 through 10.11.*, and 11.0 through 11.0.* can sometimes crash with an empty backtrace log. This ma…
Vulnerabilities was discovered in MariaDB, a SQL database server compatible with MySQL. CVE-2025-30693
Several security issues were fixed in MariaDB.
PostgreSQL could be made to crash if it received specially crafted network traffic.
PostgreSQL could be made to crash if it received specially crafted network traffic.
Cybersecurity researchers are calling attention to a new Linux cryptojacking campaign that's targeting publicly accessible Redis servers.The malicious activity…
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation. (CVE-2025-4207) References: - https://bugs.mage…
Unlimited output buffer for unauthenticated clients has been fixed in the key¢''value database Redis. For Debian 11 bullseye, this problem has been fixed in ve…
New mariadb packages are available for Slackware 15.0 and -current to fix security issues.
new module: postgresql:16
Several security issues were fixed in MySQL.
PostgreSQL could be made to execute arbitrary code if it received specially crafted input.
A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. A privileged attacker could cause a Denial-of-Service (DoS) of the Mari…
Recent vulnerabilities in BeyondTrust Remote Support ( CVE-2024-12356 ) and PostgreSQL ( CVE-2025-1094 ) are being actively exploited by threat actors and requ…
Recent vulnerabilities in BeyondTrust Remote Support ( CVE-2024-12356 ) and PostgreSQL ( CVE-2025-1094 ) are being actively exploited by threat actors and requ…
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation. (CVE-2025-1094) References: - https://bugs.mageia.org/show_bug…
Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in De…
A security issue was discovered in the PostgreSQL database system. Under certain usage patterns, improper neutralization of quoting syntax could make it possib…
Redis' Lua library commands may lead to remote code execution. (CVE-2024-46981) Redis allows denial-of-service due to malformed ACL selectors. (CVE-2024-51741)
Two security issues were discovered in Redis, a persistent key-value database, which could result in the execution of arbitrary code or denial of service.
Redis 7.2.7 Released Mon 6 Jan 2025 12:30:00 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes (CVE-2024-46981) Lua script commands may le…
Important: postgresql:15 security update
Important: postgresql:16 security update