rpm package
opensuse/python-pymongo&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/python-pymongo&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-88029 | Hig | 8.3 | < 4.18.1-1.1 | 4.18.1-1.1 | Sep 10, 2026 | Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can in | |
| CVE-2023-29483 | Hig | 7.0 | < 4.16.0-1.1 | 4.16.0-1.1 | Apr 11, 2024 | eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred | |
| CVE-2013-2132 | — | < 4.17.0-1.1 | 4.17.0-1.1 | Aug 15, 2013 | bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef." |
- affected < 4.18.1-1.1fixed 4.18.1-1.1
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can in
- affected < 4.16.0-1.1fixed 4.16.0-1.1
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred
- CVE-2013-2132Aug 15, 2013affected < 4.17.0-1.1fixed 4.17.0-1.1
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."