|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 17, 2026, 10 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 241831 | 7.5 | 危険 | daniel ptzinger TYPO3 Association |
- | TYPO3 用の Document Directorys 拡張機能における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4393 | 2012-06-26 16:18 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 241832 | 4.3 | 警告 | daniel regelein TYPO3 Association |
- | TYPO3 用の File list 拡張機能におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4391 | 2012-06-26 16:18 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 241833 | 4.3 | 警告 | frank krger TYPO3 Association |
- | TYPO3 の nl_listman 拡張におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4388 | 2012-06-26 16:18 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 241834 | 7.5 | 危険 | bookingcentre | - | Venalsur Booking Centre Booking System の hotel_tiempolibre_ext.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4386 | 2012-06-26 16:18 | 2009-12-22 | Show | GitHub Exploit DB Packet Storm |
| 241835 | 7.5 | 危険 | AlienVault | - | AlienVault OSSIM の repository/repository_attachment.php における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4375 | 2012-06-26 16:18 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 241836 | 7.5 | 危険 | AlienVault | - | AlienVault OSSIM の repository/repository_attachment.php におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2009-4374 | 2012-06-26 16:18 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 241837 | 7.5 | 危険 | AlienVault | - | AlienVault OSSIM の repository/repository_attachment.php における任意のコードを実行される脆弱性 |
CWE-Other
その他 |
CVE-2009-4373 | 2012-06-26 16:18 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 241838 | 7.5 | 危険 | AlienVault | - | AlienVault OSSIM における任意のコマンドを実行される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2009-4372 | 2012-06-26 16:18 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 241839 | 3.5 | 注意 | Drupal | - | Drupal Core の Locale モジュールにおけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4371 | 2012-06-26 16:18 | 2009-12-21 | Show | GitHub Exploit DB Packet Storm |
| 241840 | 7.5 | 危険 | fr.simon rundell TYPO3 Association |
- | TYPO3 の ste_parish_admin 拡張における SQL インジェクションの脆弱性 |
CWE-89
SQLインジェクション |
CVE-2009-4401 | 2012-06-26 16:18 | 2008-07-9 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 17, 2026, 4:15 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 268801 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10123 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268802 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail does not properly clean environment variables, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10122 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268803 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10121 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268804 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10120 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268805 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10119 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268806 | 3.3 |
LOW
Local |
firejail_project | firejail | Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10118 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268807 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10117 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 268808 | 5.9 |
MEDIUM
Network |
bluecoat |
ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware |
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connec… |
CWE-399
Resource Management Errors |
CVE-2016-10259 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |
| 268809 | 7.8 |
HIGH
Local |
synology | photo_station | Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10323 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |
| 268810 | 8.8 |
HIGH
Network |
synology | photo_station | Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. |
CWE-77
Command Injection |
CVE-2016-10322 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |