Daview Indy
Vendor:
First CVE: Apr 25, 2019 · Active for 7 years
10
Total CVEs
Bottom 1%
3.3
Avg CVEs / Year
Bottom 1%
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Daview Indy over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2019
7 years ago
Most Recent CVE
Jul 12, 2021
1,842 days ago
CVE Severity & Scoring
Daview Indy10 CVEs
100%
All CVEs353,173 CVEs
45%
40%
11%
High
Attack Vector
Local10 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required10 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7872HIGH DaviewIndy v8.98.7.0 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed format file that is mishandled by DaviewIndy. Attackers c | Jul 12, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-7818HIGH DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit | Jul 17, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7816HIGH A vulnerability in the JPEG image parsing module in DaView Indy, DaVa+, DaOffice softwares could allow an unauthenticated, remote attacker to cause an arbitrary code execution on a | Jun 30, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-7852HIGH DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed ex.j2c format file that is mishandled by Daview.exe. Attackers could exploit this and | Mar 24, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-7827HIGH DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers coul | Jul 30, 2020 | 7.8 | 24 | NO | NO |
CVE-2020-7823HIGH DaviewIndy has a Memory corruption vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary | Aug 4, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7822HIGH DaviewIndy has a Heap-based overflow vulnerability, triggered when the user opens a malformed image file that is mishandled by Daview.exe. Attackers could exploit this and arbitrar | Aug 4, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7829HIGH DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers | Jul 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-7828HIGH DaviewIndy 8.98.4 and earlier version contain Heap-based overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers | Jul 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2019-9137HIGH DaviewIndy 8.98.7 and earlier versions have a Integer overflow vulnerability, triggered when the user opens a malformed Image file that is mishandled by Daview.exe. Attackers could | Apr 25, 2019 | 7.8 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Daview Indy
Top CWEs
Versions
No cataloged versions.