Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
meder kydyraliev vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2007-6353
Integer overflow in exif.cpp in exiv2 library allows context-dependent malicious users to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Exiv2 Exiv2
NA
CVE-2007-6356
exiftags prior to 1.01 allows malicious users to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
Aertherwide Exiftags
NA
CVE-2007-6354
Unspecified vulnerability in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.
Aertherwide Exiftags
Aertherwide Exiftags 0.98
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.99
Aertherwide Exiftags 0.97
Aertherwide Exiftags 0.90
NA
CVE-2007-6355
Integer overflow in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354.
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.97
Aertherwide Exiftags
Aertherwide Exiftags 0.99
Aertherwide Exiftags 0.90
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.98
NA
CVE-2007-6351
libexif 0.6.16 and previous versions allows context-dependent malicious users to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
Libexif Project Libexif 0.6.14
Libexif Project Libexif 0.6.15
Libexif Project Libexif
NA
CVE-2007-6352
Integer overflow in libexif 0.6.16 and previous versions allows context-dependent malicious users to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Libexif Libexif
NA
CVE-2008-2696
Exiv2 0.16 allows user-assisted remote malicious users to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Exiv2 Exiv2 0.16
NA
CVE-2010-1622
SpringSource Spring Framework 2.5.x prior to 2.5.6.SEC02, 2.5.7 prior to 2.5.7.SR01, and 3.0.x prior to 3.0.3 allows remote malicious users to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Oracle Fusion Middleware 11.1.1.8.0
Oracle Fusion Middleware 7.6.2
Oracle Fusion Middleware 11.1.1.6.1
Springsource Spring Framework 2.5.0
Springsource Spring Framework 3.0.1
Springsource Spring Framework 2.5.3
Springsource Spring Framework 3.0.2
Springsource Spring Framework 2.5.5
Springsource Spring Framework 2.5.6
Springsource Spring Framework 2.5.4
Springsource Spring Framework 2.5.2
Springsource Spring Framework 2.5.7
Springsource Spring Framework 3.0.0
Springsource Spring Framework 2.5.1
1 EDB exploit
13 Github repositories
1 Article
NA
CVE-2008-6504
ParametersInterceptor in OpenSymphony XWork 2.0.x prior to 2.0.6 and 2.1.x prior to 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote malicious users to execute Object-Graph Navigation ...
Opensymphony Xwork 2.0.5
Opensymphony Xwork 2.1.0
Opensymphony Xwork 2.0.1
Opensymphony Xwork 2.0.2
Opensymphony Xwork 2.0.0
Opensymphony Xwork 2.1.1
Opensymphony Xwork 2.0.3
Opensymphony Xwork 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.0
Apache Struts 2.0.2
Apache Struts 2.0.9
Apache Struts 2.0.11
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
1 EDB exploit
NA
CVE-2007-4385
OWASP Stinger prior to 2.5 allows remote malicious users to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the valida...
Owasp Stinger
1 EDB exploit
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »