Записи DJI
9 опубликованных записей вендора dji.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read1
- CWE-129 Improper Validation of Array Index1
- CWE-291 Reliance on IP Address for Authentication1
- CWE-306 Missing Authentication for Critical Function1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2007-1074Proof of concept | Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long dji · newsbin pro | Критическая9,3 | — | 7,5 % | 22 февр. 2007 г. |
31Наблюдать | CVE-2020-29664Эксплойта нет | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a maldji · mavic 2 firmware · CWE-78 | Высокая7,8 | — | 1,5 % | 18 февр. 2021 г. |
30Наблюдать | CVE-2022-29945Эксплойта нет | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScopedji · mavic 3 firmware · CWE-319 | Высокая7,5 | — | 0,7 % | 29 апр. 2022 г. |
30Наблюдать | CVE-2026-26673Эксплойта нет | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via dji · mavic mini firmware · CWE-400 | Высокая7,5 | — | 0,6 % | 4 мар. 2026 г. |
27Наблюдать | CVE-2023-51454Эксплойта нет | A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to dji · mavic 3 pro · CWE-787 | Средняя6,8 | — | 0,2 % | 2 апр. 2024 г. |
27Наблюдать | CVE-2023-51455Эксплойта нет | A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow dji · mavic 3 pro · CWE-129 | Средняя6,8 | — | 0,2 % | 2 апр. 2024 г. |
27Наблюдать | CVE-2023-51456Эксплойта нет | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attackdji · mavic 3 pro · CWE-125 | Средняя6,8 | — | 0,2 % | 2 апр. 2024 г. |
23Наблюдать | CVE-2022-46415Эксплойта нет | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.dji · spark firmware · CWE-291 | Средняя5,9 | — | 0,9 % | 27 мар. 2023 г. |
20Наблюдать | CVE-2023-6949Эксплойта нет | A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 dji · mini 3 pro · CWE-306 | Средняя5,2 | — | 0,2 % | 2 апр. 2024 г. |
- CVE-2007-107439Наблюдать
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long
КритическаяCVSS 9,3Proof of conceptEPSS 7 %dji · newsbin pro22 февр. 2007 г.
- CVE-2020-2966431Наблюдать
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a mal
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %dji · mavic 2 firmware18 февр. 2021 г.
- CVE-2022-2994530Наблюдать
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dji · mavic 3 firmware29 апр. 2022 г.
- CVE-2026-2667330Наблюдать
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dji · mavic mini firmware4 мар. 2026 г.
- CVE-2023-5145427Наблюдать
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dji · mavic 3 pro2 апр. 2024 г.
- CVE-2023-5145527Наблюдать
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dji · mavic 3 pro2 апр. 2024 г.
- CVE-2023-5145627Наблюдать
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attack
СредняяCVSS 6,8Эксплойта нетEPSS 0 %dji · mavic 3 pro2 апр. 2024 г.
- CVE-2022-4641523Наблюдать
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %dji · spark firmware27 мар. 2023 г.
- CVE-2023-694920Наблюдать
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80
СредняяCVSS 5,2Эксплойта нетEPSS 0 %dji · mini 3 pro2 апр. 2024 г.