CVE-2026-18024
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a cr
CVSS
4.3
Medio
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Publicado: 13 ago 2026 · Última mod.: 19 ago 2026 · CWE-126
0.3%EPSS · 30 días0.3%
2026-08-142026-08-19
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-768853.1 BAJ—
——0Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service7hCVE-2026-768843.1 BAJ—
——0ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service8hCVE-2026-65933—7.7%
——2A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.7dCVE-2026-146784.3 MED22.8%
——7Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.2dCVE-2026-688195.9 MED49.8%
——15Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.4dCVE-2026-657946.5 MED48.5%
——15Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.4d