Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MongoDB MEDIUM 5.5
CVE-2014-8180

MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can caus…

Patch available
Fix from $1,600 2017-06-06
MongoDB HIGH 7.5
CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termin…

Mitigation only
Fix from $1,950 2017-04-14
MongoDB MEDIUM 5.5
CVE-2016-6494

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by rea…

Fix: 3.0.15 / 3.2.14+
Fix from $1,600 2016-10-03
MongoDB MEDIUM 5.0
CVE-2014-3971

The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in mongod in MongoDB 2.6.x before 2.6.2 allows remote atta…

Patch available
Fix from $1,600 2014-12-25
MongoDB MEDIUM 6.4
CVE-2012-6619

The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (c…

Fix: after 2.3.1
Fix from $1,600 2014-03-06
MongoDB MEDIUM 6.5
CVE-2013-3969EPSS 10%

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitiali…

Mitigation only
Fix from $1,600 2013-10-01
MongoDB MEDIUM 6.0
CVE-2013-1892EPSS 45%

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote aut…

Fix: after 2.0.8
Fix from $1,600 2013-10-01
MongoDB MEDIUM 6.5
CVE-2013-4650

MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of …

Mitigation only
Fix from $1,600 2013-07-04