Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2021-20328 Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM… Java Driver 1.13.3 / 3.11.3+ Fix from $1,6002021-02-25 HIGH 7.5 CVE-2019-20925 An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to … MongoDB 3.4.24 / 3.6.15+ Fix from $1,9502020-11-24 MEDIUM 6.5 CVE-2020-7927 Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. T… Ops Manager after 4.4.2 Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2018-20803 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathemat… MongoDB 3.4.19 / 3.6.10+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2020-7928 A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue… MongoDB 3.6.20 / 4.0.20+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2019-2393 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. T… MongoDB 3.6.15 / 4.0.13+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2018-20802 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting Quer… MongoDB 3.6.9 / 4.0.3+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2018-20804 A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon… MongoDB 3.6.13 / 4.0.10+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2018-20805 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This … MongoDB 3.6.10 / 4.0.5+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2019-20923 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript ex… MongoDB 4.0.7+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2019-20924 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the In… MongoDB 4.2.2+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2019-2392 A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to over… MongoDB 3.6.20 / 4.0.20+ Fix from $1,6002020-11-23 HIGH 7.5 CVE-2020-7925 Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec… MongoDB 4.2.9+ Fix from $1,9502020-11-23 MEDIUM 6.5 CVE-2020-7926 A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the ser… MongoDB 4.4.1+ Fix from $1,6002020-11-23 MEDIUM 6.5 CVE-2020-7923 A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the que… MongoDB 4.0.19 / 4.2.8+ Fix from $1,6002020-08-21 MEDIUM 5.3 CVE-2019-2388 In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops … Ops Manager Mitigation only Fix from $1,6002020-05-13 MEDIUM 5.3 CVE-2020-7921 Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent… MongoDB 3.6.18 / 4.0.15+ Fix from $1,6002020-05-06 MEDIUM 5.5 CVE-2020-12135 bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() par… C Driver 0.8+ Fix from $1,6002020-04-24 MEDIUM 6.5 CVE-2020-7922 X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces… Mongodb Enterprise Kubernetes Operator after 1.4.4 Fix from $1,6002020-04-09 MEDIUM 5.4 CVE-2019-2391 Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi… Js Bson 1.1.4+ Fix from $1,6002020-03-31 CRITICAL 9.8 CVE-2020-7610 All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot… Bson 1.1.4+ Fix from $2,3002020-03-30 HIGH 7.5 CVE-2015-4411EPSS 6% The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of servic… Bson 3.0.4+ Fix from $1,9502020-02-20 HIGH 7.8 CVE-2019-2390 An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship… MongoDB 3.4.22 / 3.6.14+ Fix from $1,9502019-08-30 HIGH 7.1 CVE-2019-2386 After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom… MongoDB 3.4.22 / 3.6.13+ Fix from $1,9502019-08-06 HIGH 8.1 CVE-2015-7882 Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access. MongoDB after 3.0.6 Fix from $1,9502019-07-19 HIGH 8.1 CVE-2018-16790 _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read vi… Libbson Patch available Fix from $1,9502018-09-10 HIGH 7.5 CVE-2018-13863 The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Servi… Js Bson 1.0.5+ Fix from $1,9502018-07-10 HIGH 7.0 CVE-2017-2665 The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file… MongoDB Mitigation only Fix from $1,9502018-07-06 CRITICAL 9.1 CVE-2017-15535 MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com… MongoDB 3.4.10+ Fix from $2,3002017-11-01 HIGH 7.5 CVE-2017-14227 In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at… MongoDB Mitigation only Fix from $1,9502017-09-09