Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
Urgent
Important
Warning
Warning
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
レベルソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":June 13, 2026, 6 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
201161 4.3 警告 Peter Selinger - potrace の bitmap.h の bm_new 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-369
ゼロ除算
CVE-2016-8697 2017-02-13 17:30 2016-08-8 Show GitHub Exploit DB Packet Storm
201162 5.5 警告
Local
Peter Selinger - potrace の bitmap_io.c の bm_readbody_bmp 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-8696 2017-02-13 17:30 2016-08-8 Show GitHub Exploit DB Packet Storm
201163 5.5 警告
Local
Peter Selinger - potrace の bitmap_io.c の bm_readbody_bmp 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-8695 2017-02-13 17:30 2016-08-8 Show GitHub Exploit DB Packet Storm
201164 5.5 警告
Local
Peter Selinger - potrace の bitmap_io.c の bm_readbody_bmp 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2016-8694 2017-02-13 17:30 2016-08-8 Show GitHub Exploit DB Packet Storm
201165 7.8 重要
Local
Peter Selinger - potrace の bitmap.h の bm_new 関数におけるメモリアロケーションエラーを誘発される脆弱性 CWE-119
バッファエラー
CVE-2016-8686 2017-02-13 17:30 2016-08-29 Show GitHub Exploit DB Packet Storm
201166 5.5 警告
Local
Peter Selinger - potrace の decompose.c の findnext 関数におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2016-8685 2017-02-13 17:30 2016-08-29 Show GitHub Exploit DB Packet Storm
201167 7.8 重要
Local
libquicktime - libquicktime の quicktime_read_pascal 関数における整数オーバーフローの脆弱性 CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2016-2399 2017-02-13 17:15 2016-02-23 Show GitHub Exploit DB Packet Storm
201168 6.1 警告
Network
Debian
Canonical
MoinMoin
- MoinMoin の GUI エディタのリンクダイアログにおけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9119 2017-02-13 16:59 2016-11-15 Show GitHub Exploit DB Packet Storm
201169 8.8 重要
Network
Roundcube.net - Roundcube の Password プラグインの DBMail ドライバにおけるバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2015-2181 2017-02-13 16:36 2015-02-5 Show GitHub Exploit DB Packet Storm
201170 8.8 重要
Network
Roundcube.net - Roundcube の Password プラグインの DBMail ドライバにおける任意のコマンドを実行される脆弱性 CWE-74
インジェクション
CVE-2015-2180 2017-02-13 16:36 2015-02-5 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:June 14, 2026, 4:12 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
291561 - mozilla firefox The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to seeding the Math.random function, which makes it ea… CWE-264
Permissions, Privileges, and Access Controls
CVE-2014-1516 2024-11-21 11:04 2014-03-30 Show GitHub Exploit DB Packet Storm
291562 - symantec liveupdate_administrator SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspe… CWE-89
SQL Injection
CVE-2014-1645 2024-11-21 11:04 2014-03-29 Show GitHub Exploit DB Packet Storm
291563 - symantec liveupdate_administrator The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providin… CWE-255
Credentials Management
CVE-2014-1644 2024-11-21 11:04 2014-03-29 Show GitHub Exploit DB Packet Storm
291564 - apple safari Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen dur… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2014-1303 2024-11-21 11:04 2014-03-26 Show GitHub Exploit DB Packet Storm
291565 - apple safari Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competit… NVD-CWE-noinfo
CVE-2014-1300 2024-11-21 11:04 2014-03-26 Show GitHub Exploit DB Packet Storm
291566 - mozilla firefox Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via … CWE-200
Information Exposure
CVE-2014-1515 2024-11-21 11:04 2014-03-25 Show GitHub Exploit DB Packet Storm
291567 - mozilla network_security_services The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded i… CWE-20
 Improper Input Validation 
CVE-2014-1492 2024-11-21 11:04 2014-03-25 Show GitHub Exploit DB Packet Storm
291568 - debian
mantisbt
debian_linux
mantisbt
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in … CWE-89
SQL Injection
CVE-2014-1609 2024-11-21 11:04 2014-03-21 Show GitHub Exploit DB Packet Storm
291569 9.8 CRITICAL
Network
mozilla
debian
opensuse
suse
redhat
canonical
seamonkey
firefox_esr
firefox
thunderbird
debian_linux
opensuse
suse_linux_enterprise_software_development_kit
suse_linux_enterprise_server
suse_linux_enterprise_desktop
en…
vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a … CWE-787
 Out-of-bounds Write
CVE-2014-1514 2024-11-21 11:04 2014-03-19 Show GitHub Exploit DB Packet Storm
291570 8.8 HIGH
Network
mozilla
debian
opensuse
suse
redhat
canonical
seamonkey
firefox_esr
firefox
thunderbird
debian_linux
opensuse
suse_linux_enterprise_software_development_kit
suse_linux_enterprise_desktop
suse_linux_enterprise_server
en…
TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayB… CWE-787
 Out-of-bounds Write
CVE-2014-1513 2024-11-21 11:04 2014-03-19 Show GitHub Exploit DB Packet Storm