MonetDB is a specialized column-oriented database management system with a focused vulnerability footprint concentrated in its single core product. The recurring weakness classes affecting this system span SQL injection, resource-handling issues including unbounded allocation and improper release, and assertion-based integrity checks, reflecting the complexity of query parsing, memory management, and runtime validation in a specialized database engine. Defenders deploying MonetDB should treat SQL injection vectors as a persistent class of concern and monitor resource-consumption patterns in production instances, particularly for denial-of-service vectors arising from unthrottled allocation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Monetdb over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36369HIGH An issue in the list_append component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-34967HIGH The assertion `stmt->Dbc->FirstStmt' failed in MonetDB Database Server v11.43.13. | Aug 3, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-36368HIGH An issue in the cs_bind_ubat component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-36362HIGH An issue in the rel_sequences component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-36371HIGH An issue in the GDKfree component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36370HIGH An issue in the gc_col component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36367HIGH An issue in the BLOBcmp component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36366HIGH An issue in the log_create_delta component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36365HIGH An issue in the sql_trans_copy_key component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-36364HIGH An issue in the rel_deps component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements. | Jun 22, 2023 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Monetdb.
Media articles that mention a CVE ID that affects a product developed by Monetdb — matched by CVE ID, not by vendor name.