Количество 12
Количество 12
CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow ...
GHSA-4742-mr57-2r9j
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
BDU:2025-16225
Уязвимость реализации протокола Zlib системы управления базами данных MongoDB, позволяющая нарушителю раскрыть защищаемую информацию
ROS-20260209-80-0030
Уязвимость mongodb-org
ROS-20260209-73-0023
Уязвимость mongodb-org
ALT-PU-2026-2991
ALT-PU-2026-2991: package `mongo6.0` update to version 6.0.27-alt0.p10.1
ALT-PU-2026-2895
ALT-PU-2026-2895: package `mongo6.0` update to version 6.0.27-alt1
ALT-PU-2026-2751
ALT-PU-2026-2751: package `mongo5.0` update to version 5.0.32-alt0.p10.1
ALT-PU-2026-2562
ALT-PU-2026-2562: package `mongo5.0` update to version 5.0.32-alt1
ALT-PU-2026-2951
ALT-PU-2026-2951: package `mongo7.0` update to version 7.0.30-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. | CVSS3: 7.5 | 83% Высокий | 9 месяцев назад | |
CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. | CVSS3: 7.5 | 83% Высокий | 9 месяцев назад | |
CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow ... | CVSS3: 7.5 | 83% Высокий | 9 месяцев назад | |
GHSA-4742-mr57-2r9j Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. | CVSS3: 7.5 | 83% Высокий | 9 месяцев назад | |
BDU:2025-16225 Уязвимость реализации протокола Zlib системы управления базами данных MongoDB, позволяющая нарушителю раскрыть защищаемую информацию | CVSS3: 7.5 | 83% Высокий | 9 месяцев назад | |
ROS-20260209-80-0030 Уязвимость mongodb-org | CVSS3: 7.5 | 83% Высокий | 8 месяцев назад | |
ROS-20260209-73-0023 Уязвимость mongodb-org | CVSS3: 7.5 | 83% Высокий | 8 месяцев назад | |
ALT-PU-2026-2991 ALT-PU-2026-2991: package `mongo6.0` update to version 6.0.27-alt0.p10.1 | CVSS3: 7.5 | 83% Высокий | 7 месяцев назад | |
ALT-PU-2026-2895 ALT-PU-2026-2895: package `mongo6.0` update to version 6.0.27-alt1 | CVSS3: 7.5 | 83% Высокий | 7 месяцев назад | |
ALT-PU-2026-2751 ALT-PU-2026-2751: package `mongo5.0` update to version 5.0.32-alt0.p10.1 | CVSS3: 7.5 | 83% Высокий | 7 месяцев назад | |
ALT-PU-2026-2562 ALT-PU-2026-2562: package `mongo5.0` update to version 5.0.32-alt1 | CVSS3: 7.5 | 83% Высокий | 8 месяцев назад | |
ALT-PU-2026-2951 ALT-PU-2026-2951: package `mongo7.0` update to version 7.0.30-alt1 | CVSS3: 7.5 | 7 месяцев назад |
Уязвимостей на страницу