|
You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database). |
Update Date":May 25, 2026, 2:01 p.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Impact Show |
Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 257061 | 5.5 | 警告 | シックス・アパート株式会社 | - | Movable Type におけるアクセス制限回避の脆弱性 |
CWE-264
認可・権限・アクセス制御 |
- | 2010-01-6 15:01 | 2010-01-6 | Show | GitHub Exploit DB Packet Storm |
| 257062 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Word および Open XML File Format Converter における、任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3135 | 2010-01-6 14:44 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257063 | 5 | 警告 | トレンドマイクロ 日本電気 Apache Software Foundation 富士通 サイバートラスト株式会社 サン・マイクロシステムズ ヒューレット・パッカード レッドハット |
- | Apache Tomcat の Apache HTTP Server との組合せによるディレクトリトラバーサルの脆弱性 |
CWE-22
パス・トラバーサル |
CVE-2007-0450 | 2010-01-6 14:43 | 2007-03-16 | Show | GitHub Exploit DB Packet Storm |
| 257064 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Excel および Open XML File Format Converter におけるオブジェクトを含むスプレッドシートの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3133 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257065 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Excel および Open XML File Format Converter における BIFF レコードの処理に関する任意のコードを実行される脆弱性 |
CWE-119
バッファエラー |
CVE-2009-3130 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257066 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品におけるエクセルファイルのフォーマットの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3134 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257067 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品における計算式を含むスプレッドシートの処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3132 | 2010-01-5 16:18 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257068 | 9.3 | 危険 | マイクロソフト | - | 複数の Microsoft 製品におけるセルに含まれる計算式の処理に関する任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3131 | 2010-01-5 16:17 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257069 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office Excel における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3128 | 2010-01-5 16:17 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
| 257070 | 9.3 | 危険 | マイクロソフト | - | Microsoft Office および Open XML File Format Converter における任意のコードを実行される脆弱性 |
CWE-94
コード・インジェクション |
CVE-2009-3127 | 2010-01-5 16:16 | 2009-11-10 | Show | GitHub Exploit DB Packet Storm |
Update Date:May 25, 2026, 4:01 a.m.
| No | CVSS | Level Attach Vector |
Vendor Name | Project Name | Title | CWE | CVE | Update Date | Publication Date | Show Affected | Exploit PoC Search |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 219281 | 8.8 |
HIGH
Local |
freebsd | freebsd | In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can c… |
NVD-CWE-noinfo
|
CVE-2019-5596 | 2024-11-21 13:45 | 2019-02-12 | Show | GitHub Exploit DB Packet Storm |
| 219282 | 5.5 |
MEDIUM
Local |
freebsd | freebsd | In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save registers are not properly sanitized before return from system calls, potentiall… |
CWE-459
Incomplete Cleanup |
CVE-2019-5595 | 2024-11-21 13:45 | 2019-02-12 | Show | GitHub Exploit DB Packet Storm |
| 219283 | 8.6 |
HIGH
Local |
docker linuxfoundation redhat linuxcontainers hp netapp apache opensuse d2iq fedoraproject canonical microfocus |
docker runc enterprise_linux_server openshift enterprise_linux container_development_kit kubernetes_engine lxc onesphere solidfire hci_management_node mesos leap | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to e… |
CWE-78
OS Command |
CVE-2019-5736 | 2024-11-21 13:45 | 2019-02-12 | Show | GitHub Exploit DB Packet Storm |
| 219284 | 5.9 |
MEDIUM
Network |
openbsd winscp canonical debian redhat fedoraproject apache freebsd fujitsu siemens |
openssh winscp ubuntu_linux debian_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus fedora mina_sshd freebsd m10-1_… |
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only perf… |
CWE-22
Path Traversal |
CVE-2019-6111 | 2024-11-21 13:45 | 2019-02-1 | Show | GitHub Exploit DB Packet Storm |
| 219285 | 6.8 |
MEDIUM
Network |
openbsd winscp netapp siemens |
openssh winscp element_software storage_automation_store ontap_select_deploy scalance_x204rna_firmware scalance_x204rna_eec_firmware |
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI c… |
CWE-838
Inappropriate Encoding for Output Context |
CVE-2019-6110 | 2024-11-21 13:45 | 2019-02-1 | Show | GitHub Exploit DB Packet Storm |
| 219286 | 6.8 |
MEDIUM
Network |
openbsd winscp canonical debian netapp fedoraproject redhat siemens fujitsu |
openssh winscp ubuntu_linux debian_linux element_software storage_automation_store ontap_select_deploy fedora enterprise_linux enterprise_linux_eus enterprise_linux_serv… |
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the… |
CWE-116
Improper Encoding or Escaping of Output |
CVE-2019-6109 | 2024-11-21 13:45 | 2019-02-1 | Show | GitHub Exploit DB Packet Storm |
| 219287 | 5.5 |
MEDIUM
Local |
artifex | mupdf | Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/sv… |
CWE-118
Incorrect Access of Indexable Resource ('Range Error') |
CVE-2019-6130 | 2024-11-21 13:45 | 2019-01-11 | Show | GitHub Exploit DB Packet Storm |
| 219288 | 6.5 |
MEDIUM
Network |
libpng | libpng | png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer. |
CWE-401
Missing Release of Memory after Effective Lifetime |
CVE-2019-6129 | 2024-11-21 13:45 | 2019-01-11 | Show | GitHub Exploit DB Packet Storm |
| 219289 | 8.8 |
HIGH
Network |
libtiff canonical opensuse debian |
libtiff ubuntu_linux leap debian_linux |
The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. |
CWE-401
Missing Release of Memory after Effective Lifetime |
CVE-2019-6128 | 2024-11-21 13:45 | 2019-01-11 | Show | GitHub Exploit DB Packet Storm |
| 219290 | 7.2 |
HIGH
Network |
xiaocms | xiaocms | An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be used for PHP code execution via "INTO OUTFILE" with a .php filename. |
CWE-89
SQL Injection |
CVE-2019-6127 | 2024-11-21 13:45 | 2019-01-11 | Show | GitHub Exploit DB Packet Storm |