Логотип exploitDog
bind:CVE-2025-6706
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-6706

Количество 7

Количество 7

ubuntu логотип

CVE-2025-6706

4 месяца назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2025-6706

4 месяца назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2025-6706

4 месяца назад

An authenticated user may trigger a use after free that may result in ...

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-9pjr-27w4-fm42

4 месяца назад

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
EPSS: Низкий
fstec логотип

BDU:2025-11758

4 месяца назад

Уязвимость системы управления базами данных MongoDB, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5
EPSS: Низкий
redos логотип

ROS-20250806-09

2 месяца назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий
redos логотип

ROS-20250806-08

2 месяца назад

Множественные уязвимости mongodb-org

CVSS3: 7.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-6706

An authenticated user may trigger a use after free that may result in ...

CVSS3: 5
0%
Низкий
4 месяца назад
github логотип
GHSA-9pjr-27w4-fm42

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggregation framework operation using a specific combination of rarely-used aggregation pipeline expressions. This issue affects MongoDB Server v6.0 version prior to 6.0.21, MongoDB Server v7.0 version prior to 7.0.17 and MongoDB Server v8.0 version prior to 8.0.4 when the SBE engine is enabled.

CVSS3: 5
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-11758

Уязвимость системы управления базами данных MongoDB, связанная с использованием памяти после освобождения, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5
0%
Низкий
4 месяца назад
redos логотип
ROS-20250806-09

Множественные уязвимости mongodb-org

CVSS3: 7.7
2 месяца назад
redos логотип
ROS-20250806-08

Множественные уязвимости mongodb-org

CVSS3: 7.7
2 месяца назад

Уязвимостей на страницу