NAVER kayıtları
naver üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %12
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-502 Deserialization of Untrusted Data3
- CWE-862 Missing Authorization2
- CWE-269 Improper Privilege Management1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-33592İstismar yok | NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file.naver · toolbar · CWE-20 | Kritik9,8 | — | %2,1 | 19 Tem 2021 |
39İzleyin | CVE-2024-28213İstismar yok | nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbinaver · ngrinder · CWE-502 | Kritik9,8 | — | %1,2 | 7 Mar 2024 |
39İzleyin | CVE-2020-9752İstismar yok | Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through inaver · cloud explorer · CWE-73 | Kritik9,8 | — | %1,1 | 22 Mar 2020 |
39İzleyin | CVE-2024-28212İstismar yok | nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.naver · ngrinder · CWE-502 | Kritik9,8 | — | %1,0 | 7 Mar 2024 |
39İzleyin | CVE-2025-49223Kavram kanıtı | billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to executenaver · billboard.js · CWE-1321 | Kritik9,8 | — | %0,8 | 3 Haz 2025 |
39İzleyin | CVE-2024-28211İstismar yok | nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMInaver · ngrinder · CWE-502 | Kritik9,8 | — | %0,8 | 7 Mar 2024 |
38İzleyin | CVE-2024-40618İstismar yok | Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in naver · naver whale browser · CWE-79 | Kritik9,6 | — | %0,4 | 10 Tem 2024 |
36İzleyin | CVE-2020-9753İstismar yok | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.naver · whale browser installer · CWE-347 | Kritik9,1 | — | %1,1 | 19 May 2020 |
36İzleyin | CVE-2020-9751İstismar yok | Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upnaver · cloud explorer · CWE-494 | Kritik9,1 | — | %0,5 | 3 Mar 2020 |
35İzleyin | CVE-2021-33591İstismar yok | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted Hnaver · comic viewer · CWE-489 | Yüksek8,8 | — | %1,6 | 28 May 2021 |
31İzleyin | CVE-2022-24077İstismar yok | Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.naver · cloud explorer · CWE-269 | Yüksek7,8 | — | %0,3 | 13 Haz 2022 |
30İzleyin | CVE-2019-13157İstismar yok | nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename withinaver · vaccine · CWE-22 | Yüksek7,5 | — | %1,7 | 21 Kas 2019 |
30İzleyin | CVE-2019-13156İstismar yok | NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when readinnaver · cloud explorer · CWE-121 | Yüksek7,5 | — | %1,0 | 3 Eyl 2019 |
30İzleyin | CVE-2024-28215İstismar yok | nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause onaver · ngrinder · CWE-862 | Yüksek7,5 | — | %0,5 | 7 Mar 2024 |
25İzleyin | CVE-2016-5060İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML vianaver · ngrinder · CWE-79 | Orta6,1 | — | %1,9 | 13 Ara 2016 |
24İzleyin | CVE-2026-23768İstismar yok | lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListennaver · lucy-xss-filter · CWE-918 | Orta6,1 | — | %0,2 | 16 Oca 2026 |
24İzleyin | CVE-2026-23769İstismar yok | lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigurenaver · lucy-xss-filter · CWE-79 | Orta6,1 | — | %0,2 | 16 Oca 2026 |
24İzleyin | CVE-2026-1513İstismar yok | billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.naver · billboard.js · CWE-79 | Orta6,1 | — | %0,2 | 27 Oca 2026 |
22İzleyin | CVE-2023-25632İstismar yok | The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.naver · whale browser · CWE-359 | Orta5,5 | — | %0,2 | 27 Kas 2023 |
21İzleyin | CVE-2024-28216İstismar yok | nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause onaver · ngrinder · CWE-862 | Orta5,4 | — | %0,3 | 7 Mar 2024 |
21İzleyin | CVE-2014-6980İstismar yok | The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which allnaver · line play · CWE-310 | Orta5,4 | — | %0,3 | 16 Eki 2014 |
20İzleyin | CVE-2012-4005İstismar yok | The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to obnaver · nhn japan naver line · CWE-200 | Orta5,0 | — | %1,4 | 7 Ağu 2012 |
17İzleyin | CVE-2012-5182İstismar yok | The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitivenaver · loctouch · CWE-200 | Orta4,3 | — | %1,0 | 26 Ara 2012 |
10İzleyin | CVE-2012-5183İstismar yok | The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a craftednaver · loctouch · CWE-200 | Düşük2,6 | — | %1,0 | 26 Ara 2012 |
10İzleyin | CVE-2024-28214İstismar yok | nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.naver · ngrinder · CWE-405 | Düşük2,7 | — | %0,6 | 7 Mar 2024 |
- CVE-2021-3359240Planlayın
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file.
KritikCVSS 9,8İstismar yokEPSS %2naver · toolbar19 Tem 2021
- CVE-2024-2821339İzleyin
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbi
KritikCVSS 9,8İstismar yokEPSS %1naver · ngrinder7 Mar 2024
- CVE-2020-975239İzleyin
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through i
KritikCVSS 9,8İstismar yokEPSS %1naver · cloud explorer22 Mar 2020
- CVE-2024-2821239İzleyin
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
KritikCVSS 9,8İstismar yokEPSS %1naver · ngrinder7 Mar 2024
- CVE-2025-4922339İzleyin
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute
KritikCVSS 9,8Kavram kanıtıEPSS %1naver · billboard.js3 Haz 2025
- CVE-2024-2821139İzleyin
nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI
KritikCVSS 9,8İstismar yokEPSS %1naver · ngrinder7 Mar 2024
- CVE-2024-4061838İzleyin
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in
KritikCVSS 9,6İstismar yokEPSS %0naver · naver whale browser10 Tem 2024
- CVE-2020-975336İzleyin
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
KritikCVSS 9,1İstismar yokEPSS %1naver · whale browser installer19 May 2020
- CVE-2020-975136İzleyin
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the up
KritikCVSS 9,1İstismar yokEPSS %0naver · cloud explorer3 Mar 2020
- CVE-2021-3359135İzleyin
An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary code via a crafted H
YüksekCVSS 8,8İstismar yokEPSS %2naver · comic viewer28 May 2021
- CVE-2022-2407731İzleyin
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
YüksekCVSS 7,8İstismar yokEPSS %0naver · cloud explorer13 Haz 2022
- CVE-2019-1315730İzleyin
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename withi
YüksekCVSS 7,5İstismar yokEPSS %2naver · vaccine21 Kas 2019
- CVE-2019-1315630İzleyin
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when readin
YüksekCVSS 7,5İstismar yokEPSS %1naver · cloud explorer3 Eyl 2019
- CVE-2024-2821530İzleyin
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause o
YüksekCVSS 7,5İstismar yokEPSS %1naver · ngrinder7 Mar 2024
- CVE-2016-506025İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via
OrtaCVSS 6,1İstismar yokEPSS %2naver · ngrinder13 Ara 2016
- CVE-2026-2376824İzleyin
lucy-xss-filter before commit 7c1de6d allows an attacker to induce server-side HEAD requests to arbitrary URLs when the ObjectSecurityListen
OrtaCVSS 6,1İstismar yokEPSS %0naver · lucy-xss-filter16 Oca 2026
- CVE-2026-2376924İzleyin
lucy-xss-filter before commit e5826c0 allows an attacker to execute malicious JavaScript due to improper sanitization caused by misconfigure
OrtaCVSS 6,1İstismar yokEPSS %0naver · lucy-xss-filter16 Oca 2026
- CVE-2026-151324İzleyin
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
OrtaCVSS 6,1İstismar yokEPSS %0naver · billboard.js27 Oca 2026
- CVE-2023-2563222İzleyin
The Android Mobile Whale browser app before 3.0.1.2 allows the attacker to bypass its browser unlock function via 'Open in Whale' feature.
OrtaCVSS 5,5İstismar yokEPSS %0naver · whale browser27 Kas 2023
- CVE-2024-2821621İzleyin
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause o
OrtaCVSS 5,4İstismar yokEPSS %0naver · ngrinder7 Mar 2024
- CVE-2014-698021İzleyin
The LINE PLAY (aka jp.naver.lineplay.android) application 2.3.1.1 for Android does not verify X.509 certificates from SSL servers, which all
OrtaCVSS 5,4İstismar yokEPSS %0naver · line play16 Eki 2014
- CVE-2012-400520İzleyin
The NHN Japan NAVER LINE application before 2.5.5 for Android does not properly handle implicit intents, which allows remote attackers to ob
OrtaCVSS 5,0İstismar yokEPSS %1naver · nhn japan naver line7 Ağu 2012
- CVE-2012-518217İzleyin
The Loctouch application 3.4.6 and earlier for Android does not properly handle implicit intents, which allows attackers to obtain sensitive
OrtaCVSS 4,3İstismar yokEPSS %1naver · loctouch26 Ara 2012
- CVE-2012-518310İzleyin
The Loctouch application 3.4.6 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted
DüşükCVSS 2,6İstismar yokEPSS %1naver · loctouch26 Ara 2012
- CVE-2024-2821410İzleyin
nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.
DüşükCVSS 2,7İstismar yokEPSS %1naver · ngrinder7 Mar 2024