Naver Corporation

First CVE: Aug 2, 2018Active for: 8 years
40
CVEs Published
More CVEs Published than 53% of tracked CNAs
4.4
Avg CVEs / Year
More Avg CVEs / Year than 30% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Naver Corporation as a CNA, 47.5% affect products that Naver Corporation develops as a vendor.

47.5%
52.5%
Self-reported: 19Third-party: 21

Of all the CVEs published that affect products developed by Naver Corporation, 79.2% are self-published by Naver Corporation as a CNA.

79.2%
20.8%
Self-published: 19Published by other CNAs: 5

Trends Over Time

The number and severity of CVEs published by Naver Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 2, 2018
7 years ago
Most Recent CVE
May 8, 2026
77 days ago

Top CVEs

All CVEs published by Naver Corporation as a CNA, regardless of affected vendor or product.

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypas
Jul 19, 20219.832NONO
NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.
May 8, 20267.830NONO
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
Oct 16, 20259.830NONO
billboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to execute arbitrary code or cause a Denial of Ser
Jun 4, 20259.830NONO
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
Mar 7, 20249.830NONO
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Whal
Mar 17, 20229.830NONO
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.
Mar 23, 20209.829NONO
Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer.
May 20, 20209.128NONO
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.
Mar 3, 20209.128NONO
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
Dec 30, 20259.127NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA40 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local6 (15.0%)
Network34 (85.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None29 (72.5%)
Unknown0 (0.0%)
Required11 (27.5%)
Privileges Required
Low5 (12.5%)
High1 (2.5%)
None34 (85.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Naver Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Naver Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs