Description
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.
Remediation
References
Related Vulnerabilities
WordPress Plugin Post Grid, List for WordPress-Content Views Cross-Site Scripting (1.9.0)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.12)
WordPress Plugin GD Star Rating 'de' Parameter SQL Injection (1.9.10)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0791)