Vulnerabilities > Mongodb > Mongodb > 4.2.5

DATE CVE VULNERABILITY TITLE RISK
2022-04-12 CVE-2021-32040 Out-of-bounds Write vulnerability in Mongodb
It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage.
network
low complexity
mongodb CWE-787
7.5
2022-02-04 CVE-2021-32036 Allocation of Resources Without Limits or Throttling vulnerability in Mongodb
An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention.
network
low complexity
mongodb CWE-770
7.1
2021-12-15 CVE-2021-20330 Improper Input Validation vulnerability in Mongodb
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries.
network
low complexity
mongodb CWE-20
6.5
2021-07-23 CVE-2021-20333 Improper Encoding or Escaping of Output vulnerability in Mongodb
Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split.
network
low complexity
mongodb CWE-116
5.3
2020-11-23 CVE-2020-7928 Unspecified vulnerability in Mongodb
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries.
network
low complexity
mongodb
6.5
2020-11-23 CVE-2019-2392 Integer Overflow or Wraparound vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to overflow negative values.
network
low complexity
mongodb CWE-190
6.5
2020-11-23 CVE-2020-7925 Improper Input Validation vulnerability in Mongodb
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service.
network
low complexity
mongodb CWE-20
7.5
2020-08-21 CVE-2020-7923 Improper Handling of Exceptional Conditions vulnerability in Mongodb
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear.
network
low complexity
mongodb CWE-755
6.5