İçeriğe atla
Noroxi

NAVER kayıtları

naver üreticisine ait 25 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%12
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

25 kayıt
  • CVE-2021-33592
    40Planlayın

    NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file.

    KritikCVSS 9,8İstismar yokEPSS %2

    naver · toolbar19 Tem 2021

  • CVE-2024-28213
    39İzleyin

    nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbi

    KritikCVSS 9,8İstismar yokEPSS %1

    naver · ngrinder7 Mar 2024

  • CVE-2020-9752
    39İzleyin

    Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i

    KritikCVSS 9,8İstismar yokEPSS %1

    naver · cloud explorer22 Mar 2020

  • CVE-2024-28212
    39İzleyin

    nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

    KritikCVSS 9,8İstismar yokEPSS %1

    naver · ngrinder7 Mar 2024

  • CVE-2025-49223
    39İzleyin

    billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    naver · billboard.js3 Haz 2025

  • CVE-2024-28211
    39İzleyin

    nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI

    KritikCVSS 9,8İstismar yokEPSS %1

    naver · ngrinder7 Mar 2024

  • CVE-2024-40618
    38İzleyin

    Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in

    KritikCVSS 9,6İstismar yokEPSS %0

    naver · naver whale browser10 Tem 2024

  • CVE-2020-9753
    36İzleyin

    Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.

    KritikCVSS 9,1İstismar yokEPSS %1

    naver · whale browser installer19 May 2020

  • CVE-2020-9751
    36İzleyin

    Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the up

    KritikCVSS 9,1İstismar yokEPSS %0

    naver · cloud explorer3 Mar 2020

  • CVE-2021-33591
    35İzleyin

    An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted H

    YüksekCVSS 8,8İstismar yokEPSS %2

    naver · comic viewer28 May 2021

  • CVE-2022-24077
    31İzleyin

    Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

    YüksekCVSS 7,8İstismar yokEPSS %0

    naver · cloud explorer13 Haz 2022

  • CVE-2019-13157
    30İzleyin

    nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename withi

    YüksekCVSS 7,5İstismar yokEPSS %2

    naver · vaccine21 Kas 2019

  • CVE-2019-13156
    30İzleyin

    NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when readin

    YüksekCVSS 7,5İstismar yokEPSS %1

    naver · cloud explorer3 Eyl 2019

  • CVE-2024-28215
    30İzleyin

    nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause o

    YüksekCVSS 7,5İstismar yokEPSS %1

    naver · ngrinder7 Mar 2024

  • CVE-2016-5060
    25İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via

    OrtaCVSS 6,1İstismar yokEPSS %2

    naver · ngrinder13 Ara 2016

  • CVE-2026-23768
    24İzleyin

    lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListen

    OrtaCVSS 6,1İstismar yokEPSS %0

    naver · lucy-xss-filter16 Oca 2026

  • CVE-2026-23769
    24İzleyin

    lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigure

    OrtaCVSS 6,1İstismar yokEPSS %0

    naver · lucy-xss-filter16 Oca 2026

  • CVE-2026-1513
    24İzleyin

    billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.

    OrtaCVSS 6,1İstismar yokEPSS %0

    naver · billboard.js27 Oca 2026

  • CVE-2023-25632
    22İzleyin

    The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.

    OrtaCVSS 5,5İstismar yokEPSS %0

    naver · whale browser27 Kas 2023

  • CVE-2024-28216
    21İzleyin

    nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause o

    OrtaCVSS 5,4İstismar yokEPSS %0

    naver · ngrinder7 Mar 2024

  • CVE-2014-6980
    21İzleyin

    The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which all

    OrtaCVSS 5,4İstismar yokEPSS %0

    naver · line play16 Eki 2014

  • CVE-2012-4005
    20İzleyin

    The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to ob

    OrtaCVSS 5,0İstismar yokEPSS %1

    naver · nhn japan naver line7 Ağu 2012

  • CVE-2012-5182
    17İzleyin

    The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive

    OrtaCVSS 4,3İstismar yokEPSS %1

    naver · loctouch26 Ara 2012

  • CVE-2012-5183
    10İzleyin

    The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted

    DüşükCVSS 2,6İstismar yokEPSS %1

    naver · loctouch26 Ara 2012

  • CVE-2024-28214
    10İzleyin

    nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.

    DüşükCVSS 2,7İstismar yokEPSS %1

    naver · ngrinder7 Mar 2024