You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
|
Update Date":Oct. 17, 2024, 6:02 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
201531 | 10 | 危険 | サイバートラスト株式会社 XEmacs |
- | XEmacs の glyphs-eimage.c における整数オーバーフローの脆弱性 |
CWE-189
数値処理の問題 |
CVE-2009-2688 | 2010-01-12 14:48 | 2009-08-5 | Show | GitHub Exploit DB Packet Storm |
201532 | 6.8 | 警告 | IBM | - | IBM WebSphere Application Server (WAS) におけるクロスサイトリクエストフォージェリの脆弱性 |
CWE-352
同一生成元ポリシー違反 |
CVE-2009-2746 | 2010-01-12 14:48 | 2009-11-13 | Show | GitHub Exploit DB Packet Storm |
201533 | 5 | 警告 | アップル | - | Apple Safari におけるローカル HTML ファイルを読まれる脆弱性 |
CWE-Other
その他 |
CVE-2009-2842 | 2010-01-7 12:09 | 2009-11-11 | Show | GitHub Exploit DB Packet Storm |
201534 | 5.5 | 警告 | シックス・アパート株式会社 | - | Movable Type におけるアクセス制限回避の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
- | 2010-01-6 15:01 | 2010-01-6 | Show | GitHub Exploit DB Packet Storm |
201535 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Word および Open XML File Format Converter における、任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3135 | 2010-01-6 14:44 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
201536 | 5 | 警告 | トレンドマイクロ 日本電気 Apache Software Foundation 富士通 サイバートラスト株式会社 サン・マイクロシステムズ ヒューレット・パッカード レッドハット |
- | Apache Tomcat の Apache HTTP Server との組合せによるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2007-0450 | 2010-01-6 14:43 | 2007-03-16 | Show | GitHub Exploit DB Packet Storm |
201537 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Excel および Open XML File Format Converter におけるオブジェクトを含むスプレッドシートの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3133 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
201538 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Excel および Open XML File Format Converter における BIFF レコードの処理に関する任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2009-3130 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
201539 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品におけるエクセルファイルのフォーマットの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3134 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
201540 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品における計算式を含むスプレッドシートの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3132 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
Update Date:Oct. 10, 2024, 8:13 p.m.
No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
---|---|---|---|---|---|---|---|---|---|---|---|
91 | - | - | - | Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization … Update | - | CVE-2024-49193 | 2024-10-17 05:35 | 2024-10-12 | Show | GitHub Exploit DB Packet Storm | |
92 | 7.8 |
HIGH
Local |
android | In wifi service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed Update |
CWE-862
Missing Authorization |
CVE-2023-42694 | 2024-10-17 05:35 | 2023-12-4 | Show | GitHub Exploit DB Packet Storm | |
93 | 9.8 |
CRITICAL
Network
gl-inet
|
gl-ax1800_firmware
|
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.
Update
|
CWE-281
|
Improper Preservation of Permissions
CVE-2023-47463
|
2024-10-17 05:35 |
2023-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
94 | 9.1 |
CRITICAL
Network
frrouting |
debian fedoraproject
frrouting |
debian_linux fedora
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Update
|
CWE-125
|
Out-of-bounds Read
CVE-2023-41360
|
2024-10-17 05:35 |
2023-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
95 | 7.8 |
HIGH
Local |
qualcomm |
snapdragon_888\+_5g_mobile_platform_\(sm8350-ac\)_firmware snapdragon_865\+_5g_mobile_platform_\(sm8250-ab\)_firmware wsa8845h_firmware wsa8845_firmware wsa8840_firmware wsa8835_firmwa… |
Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers. Update |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2024-23369 | 2024-10-17 05:30 | 2024-10-7 | Show | GitHub Exploit DB Packet Storm |
96 | 7.8 |
HIGH
Local |
qualcomm |
qualcomm_video_collaboration_vc1_platform_firmware wsa8815_firmware wsa8810_firmware wcn3980_firmware wcn3950_firmware wcd9375_firmware wcd9370_firmware snapdragon_auto_5g_modem-… |
Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver. Update |
CWE-119
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2024-21455 | 2024-10-17 05:30 | 2024-10-7 | Show | GitHub Exploit DB Packet Storm |
97 | 6.7 |
MEDIUM
Local |
qualcomm |
wsa8835_firmware wsa8830_firmware wcn3988_firmware wcn3980_firmware sw5100p_firmware sw5100_firmware snapdragon_auto_5g_modem-rf_gen_2_firmware qca9377_firmware qca9367_firmwa… |
Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same. Update |
CWE-416
Use After Free |
CVE-2024-23370 | 2024-10-17 05:27 | 2024-10-7 | Show | GitHub Exploit DB Packet Storm |
98 | 6.7 |
MEDIUM
Local |
qualcomm |
wsa8835_firmware wsa8830_firmware wcn3988_firmware wcn3980_firmware wcn3680b_firmware wcn3660b_firmware sw5100p_firmware sw5100_firmware snapdragon_w5\+_gen_1_wearable_platfor… |
Memory corruption during the network scan request. Update |
CWE-120
Classic Buffer Overflow |
CVE-2024-23375 | 2024-10-17 05:26 | 2024-10-7 | Show | GitHub Exploit DB Packet Storm |
99 | 6.7 |
MEDIUM
Local |
qualcomm |
wsa8835_firmware wsa8830_firmware wcn3988_firmware wcn3980_firmware wcd9380_firmware sw5100p_firmware sw5100_firmware snapdragon_w5\+_gen_1_wearable_platform_firmware snapdrag… |
Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file. Update |
CWE-787
Out-of-bounds Write |
CVE-2024-23374 | 2024-10-17 05:26 | 2024-10-7 | Show | GitHub Exploit DB Packet Storm |
100 | - | - | - | Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability allows any unauthenticated user to execute arbitrary code on the server. Version 4… New |
CWE-502
Deserialization of Untrusted Data |
CVE-2024-47836 | 2024-10-17 05:15 | 2024-10-17 | Show | GitHub Exploit DB Packet Storm |