Логотип exploitDog
bind: "CVE-2025-6706"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-6706"

Количество 6

Количество 6

ubuntu логотип

CVE-2025-6706

около 2 месяцев назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2025-6706

около 2 месяцев назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2025-6706

около 2 месяцев назад

An authenticated user may trigger a use after free that may result in ...

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-9pjr-27w4-fm42

около 1 месяца назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
redos логотип

ROS-20250806-09

5 дней назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий
redos логотип

ROS-20250806-08

5 дней назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in ...

CVSS3: 5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-9pjr-27w4-fm42

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20250806-09

Множественные уязвимости mongodb-org

CVSS3: 7.7
5 дней назад
redos логотип
ROS-20250806-08

Множественные уязвимости mongodb-org

CVSS3: 7.7
5 дней назад

Уязвимостей на страницу