|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 19, 2026, 6 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 256291 | 6.8 | 警告 | アップル GNU Project サン・マイクロシステムズ サイバートラスト株式会社 レッドハット |
- | GNU tar の contains_dot_dot() 関数におけるディレクトリトラバーサルの脆弱性 | - | CVE-2007-4131 | 2010-01-18 12:21 | 2007-08-23 | Show | GitHub Exploit DB Packet Storm |
| 256292 | 4.6 | 警告 | IBM | - | IBM DB2 の dasauto における管理者権限を持たないユーザが実行可能な脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2009-4150 | 2010-01-15 14:10 | 2009-12-2 | Show | GitHub Exploit DB Packet Storm |
| 256293 | 2.1 | 注意 | サン・マイクロシステムズ | - | Sun Solaris の ldap_cachemgr におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-Other
その他 |
CVE-2009-4080 | 2010-01-15 14:10 | 2009-11-24 | Show | GitHub Exploit DB Packet Storm |
| 256294 | 5 | 警告 | サン・マイクロシステムズ | - | Sun Solaris の sshd におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-4075 | 2010-01-15 14:09 | 2009-11-23 | Show | GitHub Exploit DB Packet Storm |
| 256295 | 2.6 | 注意 | オラクル | - | Oracle Application Server におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
- | 2010-01-14 15:01 | 2010-01-14 | Show | GitHub Exploit DB Packet Storm |
| 256296 | 9.3 | 危険 | マイクロソフト | - | Microsoft Internet Explorer に脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3672 | 2010-01-14 12:08 | 2009-11-25 | Show | GitHub Exploit DB Packet Storm |
| 256297 | 9.3 | 危険 | サン・マイクロシステムズ VMware |
- | Sun Java SE の java.lang パッケージにおける脆弱性 |
CWE-362
競合状態 |
CVE-2009-2724 | 2010-01-14 12:08 | 2009-08-10 | Show | GitHub Exploit DB Packet Storm |
| 256298 | 10 | 危険 | サン・マイクロシステムズ VMware |
- | Sun Java SE の Provider クラスにおける脆弱性 |
CWE-noinfo
情報不足 |
CVE-2009-2721 | 2010-01-14 12:08 | 2009-08-10 | Show | GitHub Exploit DB Packet Storm |
| 256299 | 5 | 警告 | 有限会社シースリー | - | WebCalenderC3 におけるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2010-0348 | 2010-01-12 15:01 | 2010-01-12 | Show | GitHub Exploit DB Packet Storm |
| 256300 | 4.3 | 警告 | 有限会社シースリー | - | WebCalenderC3 におけるクロスサイトスクリプティングの脆弱性 |
CWE-79
クロスサイト・スクリプティング(XSS) |
CVE-2010-0349 | 2010-01-12 15:00 | 2010-01-12 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 19, 2026, 4:16 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 266521 | 4.6 |
MEDIUM
Physics |
novell canonical linux |
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s… |
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device withou… |
NVD-CWE-Other
|
CVE-2016-3137 | 2024-11-21 11:49 | 2016-05-2 | Show | GitHub Exploit DB Packet Storm |
| 266522 | 4.6 |
MEDIUM
Physics |
linux novell canonical |
linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_tim… |
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and s… |
NVD-CWE-Other
|
CVE-2016-3136 | 2024-11-21 11:49 | 2016-05-2 | Show | GitHub Exploit DB Packet Storm |
| 266523 | 5.5 |
MEDIUM
Local |
novell canonical linux |
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s… |
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging fo… |
CWE-399
Resource Management Errors |
CVE-2016-3156 | 2024-11-21 11:49 | 2016-04-28 | Show | GitHub Exploit DB Packet Storm |
| 266524 | 7.8 |
HIGH
Local |
linux canonical |
linux_kernel ubuntu_linux |
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of servi… |
CWE-189 NVD-CWE-Other Numeric Errors |
CVE-2016-3135 | 2024-11-21 11:49 | 2016-04-28 | Show | GitHub Exploit DB Packet Storm |
| 266525 | 4.6 |
MEDIUM
Physics |
novell linux |
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s… |
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system cr… |
NVD-CWE-Other
|
CVE-2016-3139 | 2024-11-21 11:49 | 2016-04-28 | Show | GitHub Exploit DB Packet Storm |
| 266526 | 8.4 |
HIGH
Local |
novell linux |
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_time_extension s… |
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) vi… |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2016-3134 | 2024-11-21 11:49 | 2016-04-28 | Show | GitHub Exploit DB Packet Storm |
| 266527 | 9.8 |
CRITICAL
Network |
apache | struts | XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter. |
CWE-20
Improper Input Validation |
CVE-2016-3082 | 2024-11-21 11:49 | 2016-04-26 | Show | GitHub Exploit DB Packet Storm |
| 266528 | 8.1 |
HIGH
Network |
apache oracle |
struts siebel_e-billing |
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to … |
CWE-77
Command Injection |
CVE-2016-3081 | 2024-11-21 11:49 | 2016-04-26 | Show | GitHub Exploit DB Packet Storm |
| 266529 | 9.8 |
CRITICAL
Network |
libgd debian fedoraproject canonical opensuse php |
libgd debian_linux fedora ubuntu_linux opensuse php |
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed g… |
CWE-681
Incorrect Conversion between Numeric Types |
CVE-2016-3074 | 2024-11-21 11:49 | 2016-04-26 | Show | GitHub Exploit DB Packet Storm |
| 266530 | 6.1 |
MEDIUM
Network |
blackberry | enterprise_server | Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted … |
CWE-79
Cross-site Scripting |
CVE-2016-3126 | 2024-11-21 11:49 | 2016-04-23 | Show | GitHub Exploit DB Packet Storm |