|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 24, 2026, noon
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 256381 | 7.2 | 危険 | VMware | - | 複数の VMware 製品の vmrun における権限昇格の脆弱性 |
CWE-134
書式文字列の問題 |
CVE-2010-1139 | 2010-05-7 17:25 | 2010-04-9 | Show | GitHub Exploit DB Packet Storm |
| 256382 | 5 | 警告 | VMware | - | 複数の VMware 製品の仮想ネットワークスタックにおける重要な情報を取得される脆弱性 |
CWE-200
情報漏えい |
CVE-2010-1138 | 2010-05-7 17:25 | 2010-04-9 | Show | GitHub Exploit DB Packet Storm |
| 256383 | 8.5 | 危険 | VMware | - | 複数の VMware 製品の VMware Tools における権限昇格の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2010-1142 | 2010-05-7 17:24 | 2010-04-9 | Show | GitHub Exploit DB Packet Storm |
| 256384 | 8.5 | 危険 | VMware | - | 複数の VMware 製品の VMware Tools における任意のコードを実行される脆弱性 |
CWE-264
認可・権限・アクセス制御 |
CVE-2010-1141 | 2010-05-7 17:24 | 2010-04-9 | Show | GitHub Exploit DB Packet Storm |
| 256385 | 5 | 警告 | アップル サイバートラスト株式会社 レッドハット ターボリナックス CUPS |
- | CUPS の ippReadIO 関数におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-399
リソース管理の問題 |
CVE-2009-0949 | 2010-05-7 16:55 | 2009-06-3 | Show | GitHub Exploit DB Packet Storm |
| 256386 | 6.8 | 警告 | レッドハット サイバートラスト株式会社 ターボリナックス CUPS |
- | CUPS の TIFF イメージデコーディングルーチンにおける整数オーバーフローの脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-0163 | 2010-05-7 16:51 | 2009-04-16 | Show | GitHub Exploit DB Packet Storm |
| 256387 | 4.6 | 警告 | GNU Project サイバートラスト株式会社 レッドハット |
- | GNU cpio における大きなサイズのファイル処理によるバッファーオーバーフローの脆弱性 |
CWE-119
バッファエラー |
CVE-2005-4268 | 2010-05-7 16:51 | 2005-12-15 | Show | GitHub Exploit DB Packet Storm |
| 256388 | 4.3 | 警告 | 日本電気 Apache Software Foundation |
- | Apache Xerces C++ におけるサービス運用妨害 (DoS) の脆弱性 |
CWE-119
バッファエラー |
CVE-2009-1885 | 2010-05-6 13:47 | 2009-08-6 | Show | GitHub Exploit DB Packet Storm |
| 256389 | 6.4 | 警告 | アップル ターボリナックス CUPS |
- | CUPS における DNS リバインド攻撃を誘導される脆弱性 |
CWE-20
不適切な入力確認 |
CVE-2009-0164 | 2010-05-6 13:46 | 2009-04-24 | Show | GitHub Exploit DB Packet Storm |
| 256390 | 5 | 警告 | freedesktop.org 日本電気 サイバートラスト株式会社 レッドハット |
- | JBIG2 デコーダにおける SplashBitmap に関連する整数オーバーフローの脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-1188 | 2010-05-6 13:46 | 2009-04-23 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 24, 2026, 4:05 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 247071 | 7.5 |
HIGH
Network |
siemens | simatic_logon | A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to caus… |
CWE-20
Improper Input Validation |
CVE-2017-9938 | 2024-11-21 12:37 | 2017-08-8 | Show | GitHub Exploit DB Packet Storm |
| 247072 | 7.5 |
HIGH
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout polici… |
NVD-CWE-noinfo
|
CVE-2017-9864 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247073 | 8.8 |
HIGH
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in… |
CWE-352
Origin Validation Error |
CVE-2017-9863 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247074 | 7.5 |
HIGH
Network |
sma | sunny_explorer | An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the applicat… |
CWE-200
Information Exposure |
CVE-2017-9862 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247075 | 9.8 |
CRITICAL
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, an… |
CWE-74
Injection |
CVE-2017-9861 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247076 | 9.8 |
CRITICAL
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an… |
CWE-287
Improper Authentication |
CVE-2017-9860 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247077 | 9.8 |
CRITICAL
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked relat… |
CWE-327
Use of a Broken or Risky Cryptographic Algorithm |
CVE-2017-9859 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247078 | 7.5 |
HIGH
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. By sending crafted packets to an inverter and observing the response, active and inactive user accounts can be determined. This aids in furth… |
CWE-200
Information Exposure |
CVE-2017-9858 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247079 | 8.1 |
HIGH
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet inje… |
CWE-287
Improper Authentication |
CVE-2017-9857 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |
| 247080 | 9.8 |
CRITICAL
Network |
sma |
sunny_boy_3600_firmware sunny_boy_5000_firmware sunny_tripower_core1_firmware sunny_tripower_15000tl_firmware sunny_tripower_20000tl_firmware sunny_tripower_25000tl_firmware sunny_t… |
An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption alg… |
NVD-CWE-noinfo
|
CVE-2017-9856 | 2024-11-21 12:37 | 2017-08-6 | Show | GitHub Exploit DB Packet Storm |