DJI kayıtları
dji üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-125 Out-of-bounds Read1
- CWE-129 Improper Validation of Array Index1
- CWE-291 Reliance on IP Address for Authentication1
- CWE-306 Missing Authentication for Critical Function1
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-400 Uncontrolled Resource Consumption1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2007-1074Kavram kanıtı | Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long dji · newsbin pro | Kritik9,3 | — | %7,5 | 22 Şub 2007 |
31İzleyin | CVE-2020-29664İstismar yok | A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a maldji · mavic 2 firmware · CWE-78 | Yüksek7,8 | — | %1,5 | 18 Şub 2021 |
30İzleyin | CVE-2022-29945İstismar yok | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScopedji · mavic 3 firmware · CWE-319 | Yüksek7,5 | — | %0,7 | 29 Nis 2022 |
30İzleyin | CVE-2026-26673İstismar yok | An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via dji · mavic mini firmware · CWE-400 | Yüksek7,5 | — | %0,6 | 4 Mar 2026 |
27İzleyin | CVE-2023-51454İstismar yok | A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to dji · mavic 3 pro · CWE-787 | Orta6,8 | — | %0,2 | 2 Nis 2024 |
27İzleyin | CVE-2023-51455İstismar yok | A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow dji · mavic 3 pro · CWE-129 | Orta6,8 | — | %0,2 | 2 Nis 2024 |
27İzleyin | CVE-2023-51456İstismar yok | A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attackdji · mavic 3 pro · CWE-125 | Orta6,8 | — | %0,2 | 2 Nis 2024 |
23İzleyin | CVE-2022-46415İstismar yok | DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.dji · spark firmware · CWE-291 | Orta5,9 | — | %0,9 | 27 Mar 2023 |
20İzleyin | CVE-2023-6949İstismar yok | A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80 dji · mini 3 pro · CWE-306 | Orta5,2 | — | %0,2 | 2 Nis 2024 |
- CVE-2007-107439İzleyin
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitrary code via a long
KritikCVSS 9,3Kavram kanıtıEPSS %7dji · newsbin pro22 Şub 2007
- CVE-2020-2966431İzleyin
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a mal
YüksekCVSS 7,8İstismar yokEPSS %1dji · mavic 2 firmware18 Şub 2021
- CVE-2022-2994530İzleyin
DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope
YüksekCVSS 7,5İstismar yokEPSS %1dji · mavic 3 firmware29 Nis 2022
- CVE-2026-2667330İzleyin
An issue in DJI Mavic Mini, Spark, Mavic Air, Mini, Mini SE 0.1.00.0500 and below allows a remote attacker to cause a denial of service via
YüksekCVSS 7,5İstismar yokEPSS %1dji · mavic mini firmware4 Mar 2026
- CVE-2023-5145427İzleyin
A Out-of-bounds Write issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attacker to
OrtaCVSS 6,8İstismar yokEPSS %0dji · mavic 3 pro2 Nis 2024
- CVE-2023-5145527İzleyin
A Improper Validation of Array Index issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow
OrtaCVSS 6,8İstismar yokEPSS %0dji · mavic 3 pro2 Nis 2024
- CVE-2023-5145627İzleyin
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone devices on the port 10000 could allow an attack
OrtaCVSS 6,8İstismar yokEPSS %0dji · mavic 3 pro2 Nis 2024
- CVE-2022-4641523İzleyin
DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool.
OrtaCVSS 5,9İstismar yokEPSS %1dji · spark firmware27 Mar 2023
- CVE-2023-694920İzleyin
A Missing Authentication for Critical Function issue affecting the HTTP service running on the DJI Mavic Mini 3 Pro on the standard port 80
OrtaCVSS 5,2İstismar yokEPSS %0dji · mini 3 pro2 Nis 2024