Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 21, 2025, 6:01 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
190391 5 警告 miniweb http server - MiniWeb HTTP Server の http.c におけるディレクトリトラバーサルの脆弱性 CWE-22
パス・トラバーサル
CVE-2008-0338 2012-09-25 16:59 2008-01-17 Show GitHub Exploit DB Packet Storm
190392 7.5 危険 miniweb http server - MiniWeb HTTP Server の http.c におけるヒープベースのバッファオーバーフローの脆弱性 CWE-119
バッファエラー
CVE-2008-0337 2012-09-25 16:59 2008-01-17 Show GitHub Exploit DB Packet Storm
190393 5 警告 julien plesniak - LulieBlog における記事を削除される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0329 2012-09-25 16:59 2008-01-17 Show GitHub Exploit DB Packet Storm
190394 7.2 危険 マイクロソフト - Microsoft Windows XP 用の I2O Utility Filter ドライバにおける権限を取得される脆弱性 CWE-264
認可・権限・アクセス制御
CVE-2008-0322 2012-09-25 16:59 2008-05-13 Show GitHub Exploit DB Packet Storm
190395 7.5 危険 mapbender - Mapbender における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0301 2012-09-25 16:59 2008-03-11 Show GitHub Exploit DB Packet Storm
190396 6.8 警告 mapbender - Mapbender の mapFiler.php における任意の PHP コードを実行される脆弱性 CWE-94
コード・インジェクション
CVE-2008-0300 2012-09-25 16:59 2008-03-11 Show GitHub Exploit DB Packet Storm
190397 7.8 危険 Linux - Linux kernel におけるサービス運用妨害 (DoS) の脆弱性 CWE-119
バッファエラー
CVE-2008-0352 2012-09-25 16:59 2007-05-8 Show GitHub Exploit DB Packet Storm
190398 5 警告 Mozilla Foundation - Mozilla Firefox におけるフィッシング攻撃などを実行される脆弱性 CWE-200
情報漏えい
CVE-2008-0367 2012-09-25 16:59 2004-05-21 Show GitHub Exploit DB Packet Storm
190399 5 警告 keil-software - PhotoKorn におけるデータベース資格情報を取得される脆弱性 CWE-200
情報漏えい
CVE-2008-0297 2012-09-25 16:59 2008-01-16 Show GitHub Exploit DB Packet Storm
190400 7.5 危険 hangzhou rui-qiang - RichStrong CMS の showproduct.asp における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2008-0291 2012-09-25 16:59 2008-01-16 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 22, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
268801 - roar_smith info2www Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www. NVD-CWE-Other
CVE-2004-1341 2017-07-11 10:30 2005-04-19 Show GitHub Exploit DB Packet Storm
268802 - sun java_system_web_proxy_server Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNEC… NVD-CWE-Other
CVE-2004-1350 2017-07-11 10:30 2004-10-30 Show GitHub Exploit DB Packet Storm
268803 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attacker… NVD-CWE-Other
CVE-2004-1362 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268804 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user. NVD-CWE-Other
CVE-2004-1365 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268805 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges. CWE-255
Credentials Management
CVE-2004-1366 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268806 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script. NVD-CWE-noinfo
CVE-2004-1368 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268807 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset… NVD-CWE-Other
CVE-2004-1369 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268808 - oracle application_server
collaboration_suite
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle8i
oracle9i
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS… NVD-CWE-Other
CVE-2004-1370 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268809 - oracle application_server
collaboration_suite
database_server
e-business_suite
enterprise_manager
enterprise_manager_database_control
enterprise_manager_grid_control
oracle10g
oracle…
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2004-1371 2017-07-11 10:30 2004-08-4 Show GitHub Exploit DB Packet Storm
268810 - ibm db2_universal_database Multiple stack-based buffer overflows in IBM DB2 7.x and 8.1 allow local users to execute arbitrary code via (1) a long third argument to the rec2xml function or (2) a long filename argument to the g… NVD-CWE-Other
CVE-2004-1372 2017-07-11 10:30 2004-09-1 Show GitHub Exploit DB Packet Storm