CVE-2026-81533
- EPSS 0.21%
- Veröffentlicht 28.08.2026 20:28:02
- Zuletzt bearbeitet 11.09.2026 18:53:28
An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's op...
CVE-2026-81532
- EPSS 0.28%
- Veröffentlicht 28.08.2026 20:26:05
- Zuletzt bearbeitet 11.09.2026 18:54:31
A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded bef...
CVE-2026-19003
- EPSS 0.13%
- Veröffentlicht 12.08.2026 21:04:19
- Zuletzt bearbeitet 11.09.2026 18:54:13
A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the ...
CVE-2026-19004
- EPSS 0.36%
- Veröffentlicht 12.08.2026 20:33:13
- Zuletzt bearbeitet 11.09.2026 18:59:45
An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that r...
CVE-2026-18888
- EPSS 0.29%
- Veröffentlicht 12.08.2026 20:29:33
- Zuletzt bearbeitet 11.09.2026 18:52:17
The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may writ...
CVE-2026-19001
- EPSS 0.38%
- Veröffentlicht 12.08.2026 20:27:02
- Zuletzt bearbeitet 11.09.2026 18:53:56
The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the ...
CVE-2026-19002
- EPSS 0.29%
- Veröffentlicht 12.08.2026 20:24:35
- Zuletzt bearbeitet 11.09.2026 18:52:43
A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver ...