İçeriğe atla
Noroxi

Baidu kayıtları

baidu üreticisine ait 22 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%4,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

22 kayıt
  • CVE-2008-6444
    42Planlayın

    Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a crafted packet, pr

    KritikCVSS 10,0İstismar yokEPSS %7

    baidu · baidu hi9 Mar 2009

  • CVE-2022-31830
    41Planlayın

    Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

    KritikCVSS 9,1İstismar yokEPSS %16

    baidu · kity minder9 Haz 2022

  • CVE-2007-4105
    39İzleyin

    A certain ActiveX control in BaiduBar.dll in Baidu Soba Search Bar 5.4 allows remote attackers to execute arbitrary code via a request conta

    KritikCVSS 9,3Kavram kanıtıEPSS %7

    baidu · soba search bar31 Tem 2007

  • CVE-2021-39227
    39İzleyin

    Fix prototype pollution in the zrender merge and clone helper methods

    KritikCVSS 9,8İstismar yokEPSS %1

    baidu · zrender17 Eyl 2021

  • CVE-2025-45616
    39İzleyin

    Incorrect access control in the /admin/** API of brcc v1.2.0 allows attackers to gain access to Admin rights via a crafted request.

    KritikCVSS 9,8İstismar yokEPSS %0

    baidu · brcc5 May 2025

  • CVE-2009-2970
    38İzleyin

    Stack-based buffer overflow in the GetUiDllVersion function in an ActiveX control in UiCheck.dll before 1.0.0.7 in UiTV UiPlayer, as used in

    KritikCVSS 9,3İstismar yokEPSS %3

    uitv · uiplayer19 Eki 2009

  • CVE-2017-2219
    31İzleyin

    Untrusted search path vulnerability in the [Simeji for Windows] installer (simeji.exe) allows an attacker to gain privileges via a Trojan ho

    YüksekCVSS 7,8İstismar yokEPSS %1

    baidu · simeji9 Haz 2017

  • CVE-2017-2221
    31İzleyin

    Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan hors

    YüksekCVSS 7,8İstismar yokEPSS %1

    baidu · baidu ime4 Ağu 2017

  • CVE-2018-0692
    31İzleyin

    Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan h

    YüksekCVSS 7,8İstismar yokEPSS %1

    baidu · spark browser15 Kas 2018

  • CVE-2023-48861
    31İzleyin

    DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.d

    YüksekCVSS 7,8İstismar yokEPSS %0

    baidu · ttplayer7 Ara 2023

  • CVE-2020-22741
    30İzleyin

    An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partia

    YüksekCVSS 7,5İstismar yokEPSS %1

    baidu · xuperchain19 Tem 2021

  • CVE-2023-30637
    30İzleyin

    Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server.

    YüksekCVSS 7,5İstismar yokEPSS %1

    baidu · braft13 Nis 2023

  • CVE-2021-36631
    26İzleyin

    Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL i

    OrtaCVSS 6,7İstismar yokEPSS %0

    baidu · baidunetdisk21 Ara 2022

  • CVE-2020-18145
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.

    OrtaCVSS 6,1İstismar yokEPSS %1

    baidu · umeditor14 Tem 2021

  • CVE-2017-14744
    24İzleyin

    UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.

    OrtaCVSS 6,1İstismar yokEPSS %1

    baidu · ueditor26 Eyl 2017

  • CVE-2024-29183
    24İzleyin

    OpenRASP vulnerable to a reflected Cross-Site Scripting (XSS) attack in /login

    OrtaCVSS 6,1İstismar yokEPSS %0

    baidu · openrasp19 Nis 2024

  • CVE-2014-5349
    21İzleyin

    Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) v

    OrtaCVSS 5,0Kavram kanıtıEPSS %4

    baidu · spark browser19 Ağu 2014

  • CVE-2021-37271
    21İzleyin

    Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information

    OrtaCVSS 5,4İstismar yokEPSS %1

    baidu · ueditor28 Eyl 2021

  • CVE-2024-7342
    21İzleyin

    Baidu UEditor unrestricted upload

    OrtaCVSS 5,3İstismar yokEPSS %0

    baidu · ueditor1 Ağu 2024

  • CVE-2024-7343
    21İzleyin

    Baidu UEditor cross site scripting

    OrtaCVSS 5,3İstismar yokEPSS %0

    baidu · ueditor1 Ağu 2024

  • CVE-2014-7444
    21İzleyin

    The Baidu Navigation (aka com.baidu.navi) application 3.5.0 for Android does not verify X.509 certificates from SSL servers, which allows ma

    OrtaCVSS 5,4İstismar yokEPSS %0

    baidu · baidu navigation19 Eki 2014

  • CVE-2008-7013
    20İzleyin

    NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a

    OrtaCVSS 5,0İstismar yokEPSS %1

    baidu · baidu hi im19 Ağu 2009