Bloomberg

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    5
    High Level Threats
    0
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-32722

    Memray-generated HTML reports vulnerable to Stored XSS via unescaped command-line metadata

    Last Modified: Mar 25, 2026
    Published: Mar 18, 2026

    CVE-2025-36520

    A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to a denial of service. An attacker can send packets to trigger this vulnerability.

    Last Modified: Nov 03, 2025
    Published: Jul 22, 2025

    CVE-2025-46354

    A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Last Modified: Nov 03, 2025
    Published: Jul 22, 2025

    CVE-2025-48498

    A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when processing a number of fields used for coordination. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.

    Last Modified: Nov 03, 2025
    Published: Jul 22, 2025

    CVE-2025-36512

    A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to a database instance over TCP and send the crafted message to trigger this vulnerability.

    Last Modified: Nov 03, 2025
    Published: Jul 22, 2025
    Items Per Page