Search CVE reports
1 – 10 of 15 results
A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause any application that reads those files via the legacy API...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | — |
The bson_validate function may return early on specific inputs and incorrectly report success. This behavior could result in skipping validation for BSON data, allowing malformed or invalid UTF-8 sequences to bypass validation and...
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Not affected | Needs evaluation | Needs evaluation | Needs evaluation | — |
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a crash in applications using the MongoDB C driver.
1 affected package
mongo-c-driver
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
2 affected packages
mongo-c-driver, php-mongodb
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| mongo-c-driver | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
| php-mongodb | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |