|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 13, 2026, 12:06 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 242421 | 7.5 | 危険 | cale dunlap | - | openInvoice の auth.php における認証を回避される脆弱性 |
CWE-287
不適切な認証 |
CVE-2008-6523 | 2012-06-26 16:10 | 2009-03-25 | Show | GitHub Exploit DB Packet Storm |
| 242422 | 6.8 | 警告 | devraj mukherjee | - | Terracotta の ContentRender.class.php の RenderFile 関数におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2008-6522 | 2012-06-26 16:10 | 2009-03-25 | Show | GitHub Exploit DB Packet Storm |
| 242423 | 7.8 | 危険 | devraj mukherjee | - | Terracotta の index.php における重要な情報を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2008-6521 | 2012-06-26 16:10 | 2009-03-25 | Show | GitHub Exploit DB Packet Storm |
| 242424 | 6.2 | 警告 | compiz | - | Compiz Fusion の Expo プラグインにおけるロックされたデスクトップへアクセスされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-6514 | 2012-06-26 16:10 | 2009-03-24 | Show | GitHub Exploit DB Packet Storm |
| 242425 | 6.8 | 警告 | Andy's PHP Knowledgebase Project | - | Andy's PHP Knowledgebase の saa.php における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-6513 | 2012-06-26 16:10 | 2009-03-24 | Show | GitHub Exploit DB Packet Storm |
| 242426 | 6.8 | 警告 | - | Google Gears の WorkerPool API における同一送信元ポリシーを回避される脆弱性 |
CWE-Other
その他 |
CVE-2008-6512 | 2012-06-26 16:10 | 2009-03-24 | Show | GitHub Exploit DB Packet Storm | |
| 242427 | 4.3 | 警告 | codetoad | - | CodeToad ASP Shopping Cart Script におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2008-6500 | 2012-06-26 16:10 | 2009-03-20 | Show | GitHub Exploit DB Packet Storm |
| 242428 | 5.5 | 警告 | Apache Friends | - | XAMPP の security/xamppsecurity.php における重要な変数を偽装される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2008-6499 | 2012-06-26 16:10 | 2009-03-19 | Show | GitHub Exploit DB Packet Storm |
| 242429 | 6.8 | 警告 | Apache Friends | - | XAMPP の security/xamppsecurity.php におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2008-6498 | 2012-06-26 16:10 | 2009-03-19 | Show | GitHub Exploit DB Packet Storm |
| 242430 | 5 | 警告 | easy-news | - | Easy Content Management Publishing におけるデータベースをダウンロードされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2008-6493 | 2012-06-26 16:10 | 2009-03-19 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 13, 2026, 5:05 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 267731 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10123 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267732 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail does not properly clean environment variables, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10122 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267733 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10121 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267734 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10120 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267735 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10119 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267736 | 3.3 |
LOW
Local |
firejail_project | firejail | Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10118 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267737 | 7.8 |
HIGH
Local |
firejail_project | firejail | Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10117 | 2024-11-21 11:43 | 2017-04-13 | Show | GitHub Exploit DB Packet Storm |
| 267738 | 5.9 |
MEDIUM
Network |
bluecoat |
ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware |
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connec… |
CWE-399
Resource Management Errors |
CVE-2016-10259 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |
| 267739 | 7.8 |
HIGH
Local |
synology | photo_station | Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-10323 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |
| 267740 | 8.8 |
HIGH
Network |
synology | photo_station | Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. |
CWE-77
Command Injection |
CVE-2016-10322 | 2024-11-21 11:43 | 2017-04-11 | Show | GitHub Exploit DB Packet Storm |