VDB

CVE-2013-1892

CVE-2013-1892 PUBLISHED CVSS 6 MEDIUM

MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.

EPSS 52.17% · 98.0th percentile

Risk Scores

CVSS 2.0
6
EPSS Score
52.17%
98.0th percentile

Affected Products

VendorProductVersions
mongodbmongodb2.0.4, 2.0.7, 2.0.5
n/an/an/a
redhatenterprise_mrg2.3

Timeline

  • Apr 2, 2013 PoC Published
  • Apr 8, 2013 PoC Published
  • Oct 1, 2013 CVE Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 14, 2023 EPSS Score
  • Sep 30, 2023 EPSS Score
  • Nov 18, 2023 EPSS Score
  • Jan 5, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›