|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":June 3, 2026, 6:08 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 254061 | 9.3 | 危険 | Plone Foundation Zope Foundation |
- | Plone で使用される Zope における任意のコマンドを実行される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2011-3587 | 2011-10-13 14:45 | 2011-10-4 | Show | GitHub Exploit DB Packet Storm |
| 254062 | 9.3 | 危険 | Plone Foundation | - | Plone の CMFEditions コンポーネントにおけるサブオブジェクトにアクセスされる脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2011-4030 | 2011-10-13 14:44 | 2011-10-4 | Show | GitHub Exploit DB Packet Storm |
| 254063 | 6.8 | 警告 | Sitaram Chamarty | - | gitolite の Admin Defined Commands (ADC) 機能におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2011-1572 | 2011-10-13 14:44 | 2011-10-4 | Show | GitHub Exploit DB Packet Storm |
| 254064 | 5 | 警告 | Juan Toledo | - | EtherApe の add_conversation 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2011-3369 | 2011-10-13 14:43 | 2011-09-30 | Show | GitHub Exploit DB Packet Storm |
| 254065 | 4.9 | 警告 | DAEMON Tools | - | DAEMON Tools におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2011-3987 | 2011-10-13 12:06 | 2011-10-13 | Show | GitHub Exploit DB Packet Storm |
| 254066 | 4.3 | 警告 | Pligg | - | Pligg におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2011-3986 | 2011-10-13 12:05 | 2011-10-13 | Show | GitHub Exploit DB Packet Storm |
| 254067 | 2.6 | 注意 | Plume CMS | - | Plume におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2011-3985 | 2011-10-13 12:04 | 2011-10-13 | Show | GitHub Exploit DB Packet Storm |
| 254068 | 2.1 | 注意 | IBM | - | IBM AIX の QLogic adapters 用 Fibre Channel ドライバにおけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2011-3982 | 2011-10-12 16:09 | 2011-02-3 | Show | GitHub Exploit DB Packet Storm |
| 254069 | 9.3 | 危険 | チェック・ポイント・ソフトウェア・テクノロジーズ | - | Check Point の 複数の製品における任意のコードを実行される脆弱性 |
CWE-noinfo
情報不足 |
CVE-2011-1827 | 2011-10-12 16:05 | 2011-10-5 | Show | GitHub Exploit DB Packet Storm |
| 254070 | 7.5 | 危険 | Exim Development | - | Exim の src/dkim.c 内の dkim_exim_verify_finish 関数における任意のコードを実行される脆弱性 |
CWE-134
書式文字列の問題 |
CVE-2011-1764 | 2011-10-12 16:00 | 2011-04-29 | Show | GitHub Exploit DB Packet Storm |
Update Date:June 3, 2026, 4:18 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 246411 | 9.8 |
CRITICAL
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_tus debian_linux ubu… |
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploita… |
CWE-416
Use After Free |
CVE-2018-12378 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246412 | 9.8 |
CRITICAL
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux ubu… |
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exp… |
CWE-416
Use After Free |
CVE-2018-12377 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246413 | 9.8 |
CRITICAL
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux ubu… |
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to … |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2018-12376 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246414 | 8.1 |
HIGH
Network |
mozilla |
firefox firefox_esr thunderbird |
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the w… |
NVD-CWE-noinfo
|
CVE-2018-12368 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246415 | 4.3 |
MEDIUM
Network |
debian canonical mozilla |
debian_linux ubuntu_linux firefox thunderbird firefox_esr |
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTimi… |
CWE-20
Improper Input Validation |
CVE-2018-12367 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246416 | 8.8 |
HIGH
Network |
mozilla debian canonical |
firefox thunderbird firefox_esr debian_linux ubuntu_linux |
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which resul… |
CWE-190
Integer Overflow or Wraparound |
CVE-2018-12361 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246417 | 4.3 |
MEDIUM
Network |
mozilla canonical |
firefox ubuntu_linux |
Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability … |
CWE-200
Information Exposure |
CVE-2018-12358 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246418 | 6.5 |
MEDIUM
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux ubu… |
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability af… |
CWE-125
Out-of-bounds Read |
CVE-2018-12366 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246419 | 6.5 |
MEDIUM
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux ubu… |
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private l… |
CWE-200
Information Exposure |
CVE-2018-12365 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |
| 246420 | 8.8 |
HIGH
Network |
redhat debian canonical mozilla |
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server_aus debian_linux ubu… |
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious sit… |
CWE-352
Origin Validation Error |
CVE-2018-12364 | 2024-11-21 12:45 | 2018-10-18 | Show | GitHub Exploit DB Packet Storm |