|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 15, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 255541 | 4.3 | 警告 | シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) | - | APC Switched Rack PDU におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-4406 | 2010-03-12 15:13 | 2009-12-23 | Show | GitHub Exploit DB Packet Storm |
| 255542 | 4.3 | 警告 | シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) | - | APC Network Management Card におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2009-1798 | 2010-03-12 15:13 | 2009-12-28 | Show | GitHub Exploit DB Packet Storm |
| 255543 | 6.8 | 警告 | シュナイダーエレクトリック株式会社 (旧社名株式会社エーピーシー・ジャパン) | - | APC Network Management Card におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2009-1797 | 2010-03-12 15:12 | 2009-12-28 | Show | GitHub Exploit DB Packet Storm |
| 255544 | 6.6 | 警告 | 日立 | - | JP1/Cm2/Network Node Manager のリモートコンソールにおけるファイルパーミッションの脆弱性 |
CWE-264
認可・権限・アクセス制御 |
- | 2010-03-12 15:12 | 2010-02-26 | Show | GitHub Exploit DB Packet Storm |
| 255545 | 9.3 | 危険 | Panda Security | - | Panda Security ActiveScan におけるコンポーネントのデジタル署名を検証しない問題 |
CWE-94
コード・インジェクション |
CVE-2009-3735 | 2010-03-12 15:12 | 2010-02-12 | Show | GitHub Exploit DB Packet Storm |
| 255546 | 5 | 警告 | サイバートラスト株式会社 OpenSSL Project IBM レッドハット |
- | OpenSSL の dtls1_retrieve_buffered_fragment 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-1379 | 2010-03-12 14:44 | 2009-05-19 | Show | GitHub Exploit DB Packet Storm |
| 255547 | 5 | 警告 | サイバートラスト株式会社 OpenSSL Project IBM レッドハット |
- | OpenSSL の dtls1_process_out_of_seq_message 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-1378 | 2010-03-12 14:44 | 2009-05-19 | Show | GitHub Exploit DB Packet Storm |
| 255548 | 5 | 警告 | サイバートラスト株式会社 OpenSSL Project IBM レッドハット |
- | OpenSSL の dtls1_buffer_record 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-119
バッファエラー |
CVE-2009-1377 | 2010-03-12 14:43 | 2009-05-19 | Show | GitHub Exploit DB Packet Storm |
| 255549 | 5 | 警告 | アップル サイバートラスト株式会社 OpenSSL Project Apache Software Foundation レッドハット |
- | OpenSSL の zlib_stateful_init 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2008-1678 | 2010-03-12 14:43 | 2008-07-10 | Show | GitHub Exploit DB Packet Storm |
| 255550 | 5.8 | 警告 | OpenPNEプロジェクト | - | OpenPNE におけるアクセス制限回避の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2010-1040 | 2010-03-11 12:39 | 2010-03-5 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 15, 2026, 4:28 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 265521 | 4.3 |
MEDIUM
Network |
jenkins redhat |
jenkins openshift |
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified… |
CWE-200
Information Exposure |
CVE-2016-3723 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265522 | 4.3 |
MEDIUM
Network |
jenkins redhat |
jenkins openshift |
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name." |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-3722 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265523 | 6.5 |
MEDIUM
Network |
redhat jenkins |
openshift jenkins |
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables. |
CWE-17
Code |
CVE-2016-3721 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265524 | 7.5 |
HIGH
Network |
canonical xmlsoft debian hp opensuse |
ubuntu_linux libxml2 debian_linux icewall_file_manager icewall_federation_agent leap |
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to caus… |
CWE-20
Improper Input Validation |
CVE-2016-3705 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265525 | 7.5 |
HIGH
Network |
fedoraproject debian xstream_project |
fedora debian_linux xstream |
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStre… |
CWE-200
Information Exposure |
CVE-2016-3674 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265526 | 7.5 |
HIGH
Network |
opensuse debian hp xmlsoft canonical redhat oracle |
leap debian_linux icewall_file_manager icewall_federation_agent libxml2 ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enter… |
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consum… |
CWE-674
Uncontrolled Recursion |
CVE-2016-3627 | 2024-11-21 11:50 | 2016-05-17 | Show | GitHub Exploit DB Packet Storm |
| 265527 | 5.5 |
MEDIUM
Local |
oracle qemu canonical debian redhat citrix |
vm_server qemu ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus<… |
Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode. |
CWE-190
Integer Overflow or Wraparound |
CVE-2016-3712 | 2024-11-21 11:50 | 2016-05-12 | Show | GitHub Exploit DB Packet Storm |
| 265528 | 8.8 |
HIGH
Local |
debian hp canonical qemu oracle citrix redhat |
debian_linux helion_openstack ubuntu_linux qemu linux vm_server xenserver enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_li… |
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes … |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2016-3710 | 2024-11-21 11:50 | 2016-05-12 | Show | GitHub Exploit DB Packet Storm |
| 265529 | 5.5 |
MEDIUM
Local |
canonical redhat imagemagick |
ubuntu_linux enterprise_linux_server_supplementary_eus enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc… |
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. |
CWE-200
Information Exposure |
CVE-2016-3717 | 2024-11-21 11:50 | 2016-05-6 | Show | GitHub Exploit DB Packet Storm |
| 265530 | 3.3 |
LOW
Local |
canonical imagemagick redhat |
ubuntu_linux imagemagick enterprise_linux_server_supplementary_eus enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enter… |
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. |
CWE-264
Permissions, Privileges, and Access Controls |
CVE-2016-3716 | 2024-11-21 11:50 | 2016-05-6 | Show | GitHub Exploit DB Packet Storm |