Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Powerprove

#15642of 53,624
17.3Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2021-20218
9.8
2021-07-19
Naver · Naver Toolbar · CVE-2021-33592
**Name of the Vulnerable Software and Affected Versions** NAVER Toolbar versions prior to 4.0.30.323 **Description** The issue allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in the `filename` parameter can bypass the code signing check function. **Recommendations** For versions prior to 4.0.30.323, update to version 4.0.30.323 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `filename` parameter in the upgrade.xml file to minimize the risk of exploitation.
PT-2019-13164
7.5
2019-11-22
Naver · Naver Vaccine · CVE-2019-13157
**Name of the Vulnerable Software and Affected Versions** Naver Vaccine version 2.1.4 **Description** The issue allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within nsz archive. This is due to a problem in the nsGreen.dll component. **Recommendations** For Naver Vaccine version 2.1.4, consider updating to a newer version that addresses this issue, if available. As a temporary workaround, restrict access to the nsGreen.dll component to minimize the risk of exploitation.