|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 31, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 217891 | 4.3 | 警告 | oVirt | - | oVirt の REST API における重要な情報を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2014-0153 | 2014-09-10 12:28 | 2014-04-16 | Show | GitHub Exploit DB Packet Storm |
| 217892 | 6.8 | 警告 | oVirt | - | oVirt の Web 管理インターフェースにおける Web セッションをハイジャックされる脆弱性 |
CWE-Other
その他 |
CVE-2014-0152 | 2014-09-10 12:20 | 2014-04-8 | Show | GitHub Exploit DB Packet Storm |
| 217893 | 7.5 | 危険 | TIBCO Software | - | TIBCO Spotfire Server の Authentication モジュールにおける権限を取得される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2014-5285 | 2014-09-9 16:25 | 2014-09-3 | Show | GitHub Exploit DB Packet Storm |
| 217894 | 5 | 警告 | ARRIS Group | - | Arris 製ケーブルモデム Touchstone DG950A に情報漏えいの脆弱性 |
CWE-200
情報漏えい |
CVE-2014-4863 | 2014-09-9 16:22 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217895 | 5 | 警告 | Netmaster | - | Netmaster 製ケーブルモデム CBW700N における情報漏えいの脆弱性 |
CWE-200
情報漏えい |
CVE-2014-4862 | 2014-09-9 16:22 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217896 | 5.1 | 警告 | 株式会社エムソフト | - | EmFTP における実行ファイル読み込みに関する脆弱性 |
CWE-Other
その他 |
CVE-2014-3910 | 2014-09-9 16:21 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217897 | 5.8 | 警告 | ファルコンシステムコンサルティング株式会社 | - | WisePoint におけるセッション固定の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2014-3909 | 2014-09-9 16:21 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217898 | 5.4 | 警告 | Sensys Networks, Inc. | - | Sensys Networks VSN240 センサーの VDS および TrafficDOT におけるトラフィック制御を妨害される脆弱性 |
CWE-310
暗号の問題 |
CVE-2014-2379 | 2014-09-9 14:53 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217899 | 7.6 | 危険 | Sensys Networks, Inc. | - | Sensys Networks VSN240 センサーの VDS および TrafficDOT における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2014-2378 | 2014-09-9 14:53 | 2014-09-4 | Show | GitHub Exploit DB Packet Storm |
| 217900 | 5 | 警告 | IBM | - | IBM Cognos TM1 におけるアクセス制限を回避される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2014-0877 | 2014-09-9 11:13 | 2014-08-29 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 31, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 297311 | - | mozilla | firefox | The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Cascading Style Sheets (CSS) token sequences, which al… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-4210 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297312 | - |
mozilla suse opensuse canonical |
firefox seamonkey thunderbird linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit ubuntu_linux |
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 does not consider the compartment during property filtering, which allows remote atta… |
CWE-200
Information Exposure |
CVE-2012-4208 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297313 | - |
mozilla suse opensuse canonical redhat |
firefox seamonkey thunderbird thunderbird_esr linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit ubuntu_linux enterprise_li… |
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x befor… |
CWE-416
Use After Free |
CVE-2012-4215 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297314 | - |
mozilla suse opensuse redhat canonical |
firefox seamonkey thunderbird thunderbird_esr linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit enterprise_linux_server en… |
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.… |
CWE-416
Use After Free |
CVE-2012-4214 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297315 | - |
mozilla suse opensuse redhat canonical |
firefox seamonkey thunderbird thunderbird_esr linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit enterprise_linux_server en… |
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do not prevent use of a "top" frame name-attribut… |
CWE-79
Cross-site Scripting |
CVE-2012-4209 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297316 | - |
mozilla suse opensuse redhat debian canonical |
firefox seamonkey thunderbird thunderbird_esr linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit enterprise_linux_server en… |
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 do… |
CWE-79
Cross-site Scripting |
CVE-2012-4207 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297317 | - | mozilla | firefox | Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the … |
NVD-CWE-Other
|
CVE-2012-4206 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297318 | - |
mozilla canonical suse opensuse |
firefox seamonkey thunderbird ubuntu_linux linux_enterprise_desktop linux_enterprise_software_development_kit opensuse linux_enterprise_server |
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 assign the system principal, rather than the sandbox principal, to XMLHttpRequest objects created in sandboxes, which a… |
CWE-352
Origin Validation Error |
CVE-2012-4205 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297319 | - |
mozilla suse opensuse canonical |
firefox seamonkey thunderbird linux_enterprise_server linux_enterprise_desktop opensuse linux_enterprise_software_development_kit ubuntu_linux |
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a deni… |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2012-4204 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm | |
| 297320 | - | mozilla | firefox | The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assisted remote attackers to run arbitrary programs by le… |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2012-4203 | 2024-11-21 10:42 | 2012-11-21 | Show | GitHub Exploit DB Packet Storm |