Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
meder kydyraliev vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-6353
Integer overflow in exif.cpp in exiv2 library allows context-dependent malicious users to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Exiv2 Exiv2
Debian Debian Linux 3.1
Debian Debian Linux 4.0
Canonical Ubuntu Linux 7.04
Canonical Ubuntu Linux 7.10
Canonical Ubuntu Linux 8.04
10
CVSSv2
CVE-2007-6354
Unspecified vulnerability in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.
Aertherwide Exiftags
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.90
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.97
Aertherwide Exiftags 0.98
Aertherwide Exiftags 0.99
10
CVSSv2
CVE-2007-6355
Integer overflow in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354.
Aertherwide Exiftags
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.90
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.97
Aertherwide Exiftags 0.98
Aertherwide Exiftags 0.99
5
CVSSv2
CVE-2007-6356
exiftags prior to 1.01 allows malicious users to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
Aertherwide Exiftags
4.3
CVSSv2
CVE-2007-6351
libexif 0.6.16 and previous versions allows context-dependent malicious users to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
Libexif Project Libexif
Libexif Project Libexif 0.6.14
Libexif Project Libexif 0.6.15
6.8
CVSSv2
CVE-2007-6352
Integer overflow in libexif 0.6.16 and previous versions allows context-dependent malicious users to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Libexif Libexif
4.3
CVSSv2
CVE-2008-2696
Exiv2 0.16 allows user-assisted remote malicious users to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Exiv2 Exiv2 0.16
5
CVSSv2
CVE-2010-1870
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 up to and including 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote malicious users to modify server-side context objects an...
Apache Struts 2.0.0
Apache Struts 2.0.1
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.9
Apache Struts 2.0.10
Apache Struts 2.0.11
2 EDB exploits
1 Article
6
CVSSv2
CVE-2010-1622
SpringSource Spring Framework 2.5.x prior to 2.5.6.SEC02, 2.5.7 prior to 2.5.7.SR01, and 3.0.x prior to 3.0.3 allows remote malicious users to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Oracle Fusion Middleware 7.6.2
Oracle Fusion Middleware 11.1.1.6.1
Oracle Fusion Middleware 11.1.1.8.0
Springsource Spring Framework 2.5.0
Springsource Spring Framework 2.5.1
Springsource Spring Framework 2.5.2
Springsource Spring Framework 2.5.3
Springsource Spring Framework 2.5.4
Springsource Spring Framework 2.5.5
Springsource Spring Framework 2.5.6
Springsource Spring Framework 2.5.7
Springsource Spring Framework 3.0.0
1 EDB exploit
10 Github repositories
1 Article
5
CVSSv2
CVE-2008-6504
ParametersInterceptor in OpenSymphony XWork 2.0.x prior to 2.0.6 and 2.1.x prior to 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote malicious users to execute Object-Graph Navigation ...
Opensymphony Xwork 2.0.0
Opensymphony Xwork 2.0.1
Opensymphony Xwork 2.0.2
Opensymphony Xwork 2.0.3
Opensymphony Xwork 2.0.4
Opensymphony Xwork 2.0.5
Opensymphony Xwork 2.1.0
Opensymphony Xwork 2.1.1
Apache Struts 2.0.0
Apache Struts 2.0.2
Apache Struts 2.0.3
Apache Struts 2.0.4
1 EDB exploit
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2024-51941
CVE-2024-24417
server-side request forgery
jd edwards enterpriseone tools
google
hardcoded
CVE-2025-21569
weblogic server
IDOR
CVE-2024-24418
CVE-2024-55591
CVE-2024-49138
peoplesoft enterprise cc common application objects
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »