Comparison Overview
Harrison/Star

Harrison/Star
1285 Avenue of the Americas, 5th Floor, New York, NY, US, 10019
Last Update: 26/12/2025
Harrison and Star is a full-service, global healthcare marketing agency, combining show-stopping creative, strategic savvy, and deep scientific expertise. Over 400 employees strong, we are united to give voice to health. Our clients range from global pharmaceutical an...

TBWA\Worldwide
220 E 42nd St, New York, 10017, US
Last Update: 30/03/2026
TBWA is The Disruption Company®. We are a Collective of creative minds with an unlimited creative canvas. We create brand platforms that defy convention and compete with culture. Thanks to our trademarked Disruption® methodology, we build the world’s strongest brands. B...
Compliance Ranges Comparison

Harrison/Star







TBWA\Worldwide






Benchmark & Cyber Underwriting Signals
Incidents vs Advertising Services Industry Avg (This Year)
No incidents recorded for Harrison/Star in 2026.
Incidents vs Advertising Services Industry Avg (This Year)
No incidents recorded for TBWA\Worldwide in 2026.
Incident History - Harrison/Star (X = Date, Y = Severity)
Harrison/Star cyber incidents detection timeline including parent company and subsidiaries.
Incident History - TBWA\Worldwide (X = Date, Y = Severity)
TBWA\Worldwide cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Harrison/Star

TBWA\Worldwide
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.