Vulnerabilities
Vulnerable Software
Mongodb:  >> Mongodb  Security Vulnerabilities
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
CVSS Score
6.5
EPSS Score
0.092
Published
2013-10-01
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
CVSS Score
6.0
EPSS Score
0.491
Published
2013-10-01
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
CVSS Score
4.3
EPSS Score
0.026
Published
2013-08-15
MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database.
CVSS Score
6.5
EPSS Score
0.005
Published
2013-07-04


Contact Us

Shodan ® - All rights reserved