NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CRITICAL
HIGH
MEDIUM
LOW
CVE
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2024年11月17日12:17

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
245651 8.8 HIGH
ネットワーク
keekoonvision kk002_ip_camera_firmware Keekoon KK002 devices 1.8.12 HD have a Cross Site Request Forgery Vulnerability affecting goform/formChnUserPwd and goform/formUserMng (and the entire set of other pages). CWE-352
同一生成元ポリシー違反
CVE-2017-6180 2017-03-14 23:54 2017-03-13 表示 GitHub Exploit DB Packet Storm
245652 6.4 MEDIUM
ネットワーク
osisoft pi_web_api_2015_r2 An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the PI system without the proper permissions. CWE-264
認可・権限・アクセス制御
CVE-2016-8353 2017-03-14 23:07 2017-02-14 表示 GitHub Exploit DB Packet Storm
245653 7.2 HIGH
ネットワーク
emc isilon_onefs EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially … CWE-264
認可・権限・アクセス制御
CVE-2016-9871 2017-03-14 23:07 2017-02-3 表示 GitHub Exploit DB Packet Storm
245654 6.8 MEDIUM
ネットワーク
tesla gateway_ecu An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to comm… CWE-77
コマンドインジェクション
CVE-2016-9337 2017-03-14 22:16 2017-02-14 表示 GitHub Exploit DB Packet Storm
245655 5.3 MEDIUM
ネットワーク
visonic powerlink2_firmware An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. When a specific URL to an image is accessed, the downloaded image carries with it source code used … CWE-200
情報漏えい
CVE-2016-5813 2017-03-14 22:03 2017-02-14 表示 GitHub Exploit DB Packet Storm
245656 6.5 MEDIUM
ネットワーク
hikvision ds-76xxx_series_firmware
ds-77xxx_series_firmware
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request… CWE-119
バッファエラー
CVE-2015-4408 2017-03-14 21:57 2017-03-13 表示 GitHub Exploit DB Packet Storm
245657 6.5 MEDIUM
ネットワーク
hikvision ds-76xxx_series_firmware
ds-77xxx_series_firmware
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request… CWE-119
バッファエラー
CVE-2015-4409 2017-03-14 21:57 2017-03-13 表示 GitHub Exploit DB Packet Storm
245658 6.5 MEDIUM
ネットワーク
hikvision ds-76xxx_series_firmware
ds-77xxx_series_firmware
Buffer overflow on Hikvision NVR DS-76xxNI-E1/2 and DS-77xxxNI-E4 devices before 3.4.0 allows remote authenticated users to cause a denial of service (service interruption) via a crafted HTTP request… CWE-119
バッファエラー
CVE-2015-4407 2017-03-14 21:56 2017-03-13 表示 GitHub Exploit DB Packet Storm
245659 6.1 MEDIUM
ネットワーク
qbittorrent qbittorrent WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS. CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6503 2017-03-14 10:59 2017-03-6 表示 GitHub Exploit DB Packet Storm
245660 6.1 MEDIUM
ネットワーク
wuhu_project wuhu Gargaj/wuhu through 2017-03-08 is vulnerable to a reflected XSS in wuhu-master/www_admin/users.php (id parameter). CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6544 2017-03-14 10:59 2017-03-9 表示 GitHub Exploit DB Packet Storm
245661 7.5 HIGH
ネットワーク
tiki tikiwiki_cms\/groupware A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner URL field. CWE-200
情報漏えい
CVE-2016-10143 2017-03-14 10:59 2017-01-20 表示 GitHub Exploit DB Packet Storm
245662 10.0 CRITICAL
ネットワーク
hp operations_manager HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. CWE-94
コード・インジェクション
CVE-2016-1985 2017-03-14 10:59 2016-01-31 表示 GitHub Exploit DB Packet Storm
245663 5.4 MEDIUM
ネットワーク
ibm urbancode_deploy IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality poten… CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-9006 2017-03-14 10:59 2017-03-9 表示 GitHub Exploit DB Packet Storm
245664 7.5 HIGH
ネットワーク
ibm jazz_reporting_service Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote attackers to cause a denial of service (Report Builder… NVD-CWE-noinfo
CVE-2015-7464 2017-03-14 10:59 2016-01-29 表示 GitHub Exploit DB Packet Storm
245665 5.0 MEDIUM
隣接
emerson se4801t0x_redundant_wireless_i\/o_card_firmware
se4801t1x_simplex_wireless_i\/o_card_firmware
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the D… CWE-254
セキュリティ機能
CVE-2016-9347 2017-03-14 01:52 2017-02-14 表示 GitHub Exploit DB Packet Storm
245666 5.5 MEDIUM
ローカル
partclone_project partclone partclone.chkimg in partclone 0.2.89 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image header. An attacker may be able to launch a 'Denial o… CWE-119
バッファエラー
CVE-2017-6596 2017-03-14 01:39 2017-03-10 表示 GitHub Exploit DB Packet Storm
245667 7.5 HIGH
ネットワーク
op-tee
libtom
op-tee_os
libtomcrypt
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes i… CWE-20
不適切な入力確認
CVE-2016-6129 2017-03-14 00:24 2017-02-14 表示 GitHub Exploit DB Packet Storm
245668 9.8 CRITICAL
ネットワーク
serialize-to-js_project serialize-to-js An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaS… CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2017-5954 2017-03-14 00:23 2017-02-10 表示 GitHub Exploit DB Packet Storm
245669 10.0 CRITICAL
ネットワーク
mrf web_panel An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use… CWE-78
OSコマンド・インジェクション
CVE-2016-10043 2017-03-13 23:59 2017-02-1 表示 GitHub Exploit DB Packet Storm
245670 7.2 HIGH
ネットワーク
sophos web_appliance The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occu… CWE-77
コマンドインジェクション
CVE-2016-9554 2017-03-13 23:58 2017-01-28 表示 GitHub Exploit DB Packet Storm
245671 6.1 MEDIUM
ネットワーク
epiceditor_project epiceditor EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document. CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6589 2017-03-11 04:31 2017-03-10 表示 GitHub Exploit DB Packet Storm
245672 6.5 MEDIUM
ネットワーク
splunk splunk Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Ligh… CWE-20
不適切な入力確認
CVE-2017-5880 2017-03-10 05:28 2017-02-4 表示 GitHub Exploit DB Packet Storm
245673 5.3 MEDIUM
ネットワーク
ibm qradar_incident_forensics
qradar_security_information_and_event_manager
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533. CWE-200
情報漏えい
CVE-2016-9720 2017-03-10 04:28 2017-03-8 表示 GitHub Exploit DB Packet Storm
245674 6.1 MEDIUM
ネットワーク
finecms_project finecms andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php. CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2017-6511 2017-03-10 04:00 2017-03-8 表示 GitHub Exploit DB Packet Storm
245675 7.5 HIGH
ネットワーク
lenovo thinkserver_firmware Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77. CWE-284
不適切なアクセス制御
CVE-2016-8236 2017-03-10 03:59 2017-03-4 表示 GitHub Exploit DB Packet Storm
245676 7.5 HIGH
ネットワーク
blackberry good_control_server An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys … CWE-200
情報漏えい
CVE-2016-3127 2017-03-10 03:58 2017-03-4 表示 GitHub Exploit DB Packet Storm
245677 9.8 CRITICAL
ネットワーク
festivaltts4r_project festivaltts4r The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2) to_mp3 method in lib/festivaltts4r/festival4r.rb. CWE-77
コマンドインジェクション
CVE-2016-10194 2017-03-10 03:56 2017-03-4 表示 GitHub Exploit DB Packet Storm
245678 8.8 HIGH
ネットワーク
ibm qradar_incident_forensics
qradar_security_information_and_event_manager
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulne… CWE-20
不適切な入力確認
CVE-2016-9726 2017-03-10 03:55 2017-03-8 表示 GitHub Exploit DB Packet Storm
245679 8.5 HIGH
ネットワーク
ibm qradar_incident_forensics
qradar_security_information_and_event_manager
IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute… CWE-20
不適切な入力確認
CVE-2016-9727 2017-03-10 03:54 2017-03-8 表示 GitHub Exploit DB Packet Storm
245680 4.3 MEDIUM
ネットワーク
ibm qradar_incident_forensics
qradar_security_information_and_event_manager
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trus… CWE-352
同一生成元ポリシー違反
CVE-2016-9730 2017-03-10 03:50 2017-03-8 表示 GitHub Exploit DB Packet Storm
245681 9.8 CRITICAL
ネットワーク
emc documentum_eroom EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified pas… CWE-640
パスワードを忘れた場合の脆弱なパスワードリカバリの仕組み
CVE-2017-2766 2017-03-10 03:40 2017-02-3 表示 GitHub Exploit DB Packet Storm
245682 2.9 LOW
ローカル
ibm maximo_asset_management IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a local attacker to obtain sensitive information using HTTP Header Injection. IBM Reference #: 1998053. CWE-200
情報漏えい
CVE-2017-1124 2017-03-10 03:38 2017-03-8 表示 GitHub Exploit DB Packet Storm
245683 6.5 MEDIUM
隣接
asus rt-n56u_firmware An issue was discovered on the ASUS RT-N56U Wireless Router with Firmware 3.0.0.4.374_979. When executing an "nmap -O" command that specifies an IP address of an affected device, one can crash the de… NVD-CWE-noinfo
CVE-2017-5632 2017-03-10 03:37 2017-01-30 表示 GitHub Exploit DB Packet Storm
245684 7.5 HIGH
ネットワーク
ca unified_infrastructure_management Directory traversal vulnerability in diag.jsp file in CA Unified Infrastructure Management (formerly CA Nimsoft Monitor) 8.4 SP1 and earlier and CA Unified Infrastructure Management Snap (formerly CA… CWE-22
パス・トラバーサル
CVE-2016-9164 2017-03-10 03:32 2017-03-8 表示 GitHub Exploit DB Packet Storm
245685 4.6 MEDIUM
ネットワーク
ibm tivoli_monitoring IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223. CWE-254
セキュリティ機能
CVE-2016-5933 2017-03-10 02:56 2017-03-9 表示 GitHub Exploit DB Packet Storm
245686 6.5 MEDIUM
ネットワーク
ibm websphere_mq IBM WebSphere MQ 8.0 could allow an authenticated user with queue manager permissions to cause a segmentation fault which would result in the box having to be rebooted to resume normal operations. IB… CWE-119
バッファエラー
CVE-2016-8971 2017-03-10 01:54 2017-03-8 表示 GitHub Exploit DB Packet Storm
245687 7.8 HIGH
ローカル
ibm qradar_security_information_and_event_manager IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340. CWE-320
鍵管理のエラー
CVE-2016-2880 2017-03-9 11:59 2017-03-2 表示 GitHub Exploit DB Packet Storm
245688 6.1 MEDIUM
ネットワーク
cloudera hue Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in th… CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-4946 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245689 5.3 MEDIUM
ネットワーク
cloudera hue Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete. CWE-200
情報漏えい
CVE-2016-4947 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245690 6.1 MEDIUM
ネットワーク
cloudera manager Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a t… CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2016-4948 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245691 7.5 HIGH
ネットワーク
cloudera manager Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename parameter to /cmf/process/<process_id>/logs. CWE-200
情報漏えい
CVE-2016-4949 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245692 7.5 HIGH
ネットワーク
cloudera manager Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions. CWE-200
情報漏えい
CVE-2016-4950 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245693 5.5 MEDIUM
ローカル
openbsd openbsd OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system call. CWE-189
数値処理の問題
CVE-2016-6242 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245694 5.5 MEDIUM
ローカル
openbsd openbsd thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp parameter of the __thrsleep system call. CWE-20
不適切な入力確認
CVE-2016-6243 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245695 5.5 MEDIUM
ローカル
openbsd openbsd OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system call. NVD-CWE-noinfo
CVE-2016-6245 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245696 4.4 MEDIUM
ローカル
openbsd openbsd OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic) by mounting a tmpfs with a VNOVAL in the (1) username, (2) groupname, or (3) … CWE-20
不適切な入力確認
CVE-2016-6246 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245697 5.5 MEDIUM
ローカル
openbsd openbsd OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist. CWE-20
不適切な入力確認
CVE-2016-6247 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245698 5.5 MEDIUM
ローカル
openbsd openbsd OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9. CWE-476
NULL ポインタデリファレンス
CVE-2016-6350 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245699 5.5 MEDIUM
ローカル
openbsd openbsd Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping… CWE-190
整数オーバーフローまたはラップアラウンド
CVE-2016-6522 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm
245700 5.3 MEDIUM
ネットワーク
ibm qradar_security_information_and_event_manager IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources from external sites, avoiding the need to duplicate … CWE-200
情報漏えい
CVE-2016-9725 2017-03-9 11:59 2017-03-8 表示 GitHub Exploit DB Packet Storm