Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2016-3104
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.
0
Attacker Value
Unknown
CVE-2013-3969
Disclosure Date: October 01, 2013 (last updated October 05, 2023)
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
0
Attacker Value
Unknown
CVE-2013-2132
Disclosure Date: August 15, 2013 (last updated October 05, 2023)
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
0
Attacker Value
Unknown
CVE-2013-4650
Disclosure Date: July 04, 2013 (last updated October 05, 2023)
MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database.
0