Vulnerabilities > Mongodb > Mongodb > 2.4.1

DATE CVE VULNERABILITY TITLE RISK
2022-02-04 CVE-2021-32036 Allocation of Resources Without Limits or Throttling vulnerability in Mongodb
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention.
network
low complexity
mongodb CWE-770
7.1
2016-10-03 CVE-2016-6494 Information Exposure vulnerability in multiple products
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
local
low complexity
mongodb fedoraproject CWE-200
5.5
2015-03-30 CVE-2015-1609 Improper Input Validation vulnerability in multiple products
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
network
low complexity
fedoraproject mongodb CWE-20
5.0
2013-10-01 CVE-2013-3969 Resource Management Errors vulnerability in Mongodb
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.
network
low complexity
mongodb CWE-399
6.5
2013-07-04 CVE-2013-4650 Permissions, Privileges, and Access Controls vulnerability in Mongodb
MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database.
network
low complexity
mongodb CWE-264
6.5