Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
meder kydyraliev vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2007-6353
Integer overflow in exif.cpp in exiv2 library allows context-dependent malicious users to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
Exiv2 Exiv2
445
VMScore
CVE-2007-6356
exiftags prior to 1.01 allows malicious users to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.
Aertherwide Exiftags
890
VMScore
CVE-2007-6354
Unspecified vulnerability in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6355.
Aertherwide Exiftags
Aertherwide Exiftags 0.98
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.99
Aertherwide Exiftags 0.97
Aertherwide Exiftags 0.90
890
VMScore
CVE-2007-6355
Integer overflow in exiftags prior to 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal memory access," a different vulnerability than CVE-2007-6354.
Aertherwide Exiftags 0.95
Aertherwide Exiftags 0.97
Aertherwide Exiftags
Aertherwide Exiftags 0.99
Aertherwide Exiftags 0.90
Aertherwide Exiftags 0.80
Aertherwide Exiftags 0.92
Aertherwide Exiftags 0.91
Aertherwide Exiftags 0.94
Aertherwide Exiftags 0.93
Aertherwide Exiftags 0.96
Aertherwide Exiftags 0.98
605
VMScore
CVE-2007-6352
Integer overflow in libexif 0.6.16 and previous versions allows context-dependent malicious users to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.
Libexif Libexif
383
VMScore
CVE-2007-6351
libexif 0.6.16 and previous versions allows context-dependent malicious users to cause a denial of service (infinite recursion) via an image file with crafted EXIF tags, possibly involving the exif_loader_write function in exif_loader.c.
Libexif Project Libexif 0.6.14
Libexif Project Libexif 0.6.15
Libexif Project Libexif
383
VMScore
CVE-2008-2696
Exiv2 0.16 allows user-assisted remote malicious users to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.
Exiv2 Exiv2 0.16
609
VMScore
CVE-2010-1622
SpringSource Spring Framework 2.5.x prior to 2.5.6.SEC02, 2.5.7 prior to 2.5.7.SR01, and 3.0.x prior to 3.0.3 allows remote malicious users to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
Oracle Fusion Middleware 11.1.1.8.0
Oracle Fusion Middleware 7.6.2
Oracle Fusion Middleware 11.1.1.6.1
Springsource Spring Framework 2.5.0
Springsource Spring Framework 3.0.1
Springsource Spring Framework 2.5.3
Springsource Spring Framework 3.0.2
Springsource Spring Framework 2.5.5
Springsource Spring Framework 2.5.6
Springsource Spring Framework 2.5.4
Springsource Spring Framework 2.5.2
Springsource Spring Framework 2.5.7
Springsource Spring Framework 3.0.0
Springsource Spring Framework 2.5.1
1 EDB exploit
13 Github repositories
1 Article
685
VMScore
CVE-2007-4385
OWASP Stinger prior to 2.5 allows remote malicious users to bypass input validation routines by using multipart encoded requests instead of form-urlencoded requests. NOTE: this might be used to expose vulnerabilities in applications that would otherwise be protected by the valida...
Owasp Stinger
1 EDB exploit
505
VMScore
CVE-2008-6504
ParametersInterceptor in OpenSymphony XWork 2.0.x prior to 2.0.6 and 2.1.x prior to 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote malicious users to execute Object-Graph Navigation ...
Opensymphony Xwork 2.0.5
Opensymphony Xwork 2.1.0
Opensymphony Xwork 2.0.1
Opensymphony Xwork 2.0.2
Opensymphony Xwork 2.0.0
Opensymphony Xwork 2.1.1
Opensymphony Xwork 2.0.3
Opensymphony Xwork 2.0.4
Apache Struts 2.0.5
Apache Struts 2.0.6
Apache Struts 2.0.0
Apache Struts 2.0.2
Apache Struts 2.0.9
Apache Struts 2.0.11
Apache Struts 2.0.7
Apache Struts 2.0.8
Apache Struts 2.0.3
Apache Struts 2.0.4
Apache Struts 2.0.11.1
Apache Struts 2.0.11.2
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »