Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Java Driver MEDIUM 6.8
CVE-2021-20328

Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM…

Fix: 1.13.3 / 3.11.3+
Fix from $1,600 2021-02-25
MongoDB HIGH 7.5
CVE-2019-20925

An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to …

Fix: 3.4.24 / 3.6.15+
Fix from $1,950 2020-11-24
Ops Manager MEDIUM 6.5
CVE-2020-7927

Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. T…

Fix: after 4.4.2
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2018-20803

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathemat…

Fix: 3.4.19 / 3.6.10+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2020-7928

A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue…

Fix: 3.6.20 / 4.0.20+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2019-2393

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. T…

Fix: 3.6.15 / 4.0.13+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2018-20802

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting Quer…

Fix: 3.6.9 / 4.0.3+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2018-20804

A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon…

Fix: 3.6.13 / 4.0.10+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2018-20805

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This …

Fix: 3.6.10 / 4.0.5+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2019-20923

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript ex…

Fix: 4.0.7+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2019-20924

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the In…

Fix: 4.2.2+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2019-2392

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to over…

Fix: 3.6.20 / 4.0.20+
Fix from $1,600 2020-11-23
MongoDB HIGH 7.5
CVE-2020-7925

Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec…

Fix: 4.2.9+
Fix from $1,950 2020-11-23
MongoDB MEDIUM 6.5
CVE-2020-7926

A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the ser…

Fix: 4.4.1+
Fix from $1,600 2020-11-23
MongoDB MEDIUM 6.5
CVE-2020-7923

A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the que…

Fix: 4.0.19 / 4.2.8+
Fix from $1,600 2020-08-21
Ops Manager MEDIUM 5.3
CVE-2019-2388

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops …

Mitigation only
Fix from $1,600 2020-05-13
MongoDB MEDIUM 5.3
CVE-2020-7921

Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent…

Fix: 3.6.18 / 4.0.15+
Fix from $1,600 2020-05-06
C Driver MEDIUM 5.5
CVE-2020-12135

bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() par…

Fix: 0.8+
Fix from $1,600 2020-04-24
Mongodb Enterprise Kubernetes Operator MEDIUM 6.5
CVE-2020-7922

X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces…

Fix: after 1.4.4
Fix from $1,600 2020-04-09
Js Bson MEDIUM 5.4
CVE-2019-2391

Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi…

Fix: 1.1.4+
Fix from $1,600 2020-03-31
Bson CRITICAL 9.8
CVE-2020-7610

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot…

Fix: 1.1.4+
Fix from $2,300 2020-03-30
Bson HIGH 7.5
CVE-2015-4411EPSS 6%

The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of servic…

Fix: 3.0.4+
Fix from $1,950 2020-02-20
MongoDB HIGH 7.8
CVE-2019-2390

An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship…

Fix: 3.4.22 / 3.6.14+
Fix from $1,950 2019-08-30
MongoDB HIGH 7.1
CVE-2019-2386

After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom…

Fix: 3.4.22 / 3.6.13+
Fix from $1,950 2019-08-06
MongoDB HIGH 8.1
CVE-2015-7882

Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.

Fix: after 3.0.6
Fix from $1,950 2019-07-19
Libbson HIGH 8.1
CVE-2018-16790

_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read vi…

Patch available
Fix from $1,950 2018-09-10
Js Bson HIGH 7.5
CVE-2018-13863

The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Servi…

Fix: 1.0.5+
Fix from $1,950 2018-07-10
MongoDB HIGH 7.0
CVE-2017-2665

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…

Mitigation only
Fix from $1,950 2018-07-06
MongoDB CRITICAL 9.1
CVE-2017-15535

MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…

Fix: 3.4.10+
Fix from $2,300 2017-11-01
MongoDB HIGH 7.5
CVE-2017-14227

In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…

Mitigation only
Fix from $1,950 2017-09-09