Skip to content
Noroxi

DJI records

9 published records for vendor dji.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • CVE-2007-1074
    39Monitor

    Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long

    CriticalCVSS 9.3Proof of conceptEPSS 7%

    dji · newsbin proFeb 22, 2007

  • A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a mal

    HighCVSS 7.8No exploitEPSS 1%

    dji · mavic 2 firmwareFeb 18, 2021

  • DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope

    HighCVSS 7.5No exploitEPSS 1%

    dji · mavic 3 firmwareApr 29, 2022

  • An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via

    HighCVSS 7.5No exploitEPSS 1%

    dji · mavic mini firmwareMar 4, 2026

  • A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to

    MediumCVSS 6.8No exploitEPSS 0%

    dji · mavic 3 proApr 2, 2024

  • A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow

    MediumCVSS 6.8No exploitEPSS 0%

    dji · mavic 3 proApr 2, 2024

  • A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attack

    MediumCVSS 6.8No exploitEPSS 0%

    dji · mavic 3 proApr 2, 2024

  • DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.

    MediumCVSS 5.9No exploitEPSS 1%

    dji · spark firmwareMar 27, 2023

  • CVE-2023-6949
    20Monitor

    A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80

    MediumCVSS 5.2No exploitEPSS 0%

    dji · mini 3 proApr 2, 2024