NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2026年4月26日4:08

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
312451 5.0 MEDIUM
mcafee epolicy_orchestrator Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request. NVD-CWE-Other
CVE-2003-0610 2008-09-11 04:19 2003-08-27 表示 GitHub Exploit DB Packet Storm
312452 4.6 MEDIUM
zblast zblast Buffer overflow in zblast-svgalib of zblast 1.2.1 and earlier allows local users to execute arbitrary code via the high score file. NVD-CWE-Other
CVE-2003-0613 2008-09-11 04:19 2003-08-27 表示 GitHub Exploit DB Packet Storm
312453 5.0 MEDIUM
nokia sgsn_dx200 SNMP daemon in the DX200 based network element for Nokia Serving GPRS support node (SGSN) allows remote attackers to read SNMP options via arbitrary community strings. NVD-CWE-Other
CVE-2003-0137 2008-09-11 04:18 2003-03-18 表示 GitHub Exploit DB Packet Storm
312454 7.2 HIGH
mcafee epolicy_orchestrator The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username a… NVD-CWE-Other
CVE-2003-0148 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312455 7.5 HIGH
mcafee epolicy_orchestrator Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters. NVD-CWE-Other
CVE-2003-0149 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312456 7.2 HIGH
apple mac_os_x
mac_os_x_server
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a d… NVD-CWE-Other
CVE-2003-0171 2008-09-11 04:18 2003-05-5 表示 GitHub Exploit DB Packet Storm
312457 7.2 HIGH
xfsdump
sgi
xfsdump
irix
xfsdq in xfsdump does not create quota information files securely, which allows local users to gain root privileges. NVD-CWE-Other
CVE-2003-0173 2008-09-11 04:18 2003-05-5 表示 GitHub Exploit DB Packet Storm
312458 6.4 MEDIUM
apple mac_os_x
mac_os_x_server
Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files. NVD-CWE-Other
CVE-2003-0198 2008-09-11 04:18 2003-05-5 表示 GitHub Exploit DB Packet Storm
312459 2.1 LOW
gs-common gs-common ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files. NVD-CWE-Other
CVE-2003-0207 2008-09-11 04:18 2003-05-5 表示 GitHub Exploit DB Packet Storm
312460 9.3 HIGH
cisco catos Unknown vulnerability in Cisco Catalyst 7.5(1) allows local users to bypass authentication and gain access to the enable mode without a password. NVD-CWE-noinfo
CWE-287
不適切な認証
CVE-2003-0216 2008-09-11 04:18 2003-05-12 表示 GitHub Exploit DB Packet Storm
312461 7.5 HIGH
happycgi happymall Happycgi.com Happymall 4.3 and 4.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter for the (1) normal_html.cgi or (2) member_html.cgi scripts. NVD-CWE-Other
CVE-2003-0243 2008-09-11 04:18 2003-05-27 表示 GitHub Exploit DB Packet Storm
312462 7.5 HIGH
kde kopete The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands. NVD-CWE-Other
CVE-2003-0256 2008-09-11 04:18 2003-05-27 表示 GitHub Exploit DB Packet Storm
312463 4.6 MEDIUM
fuzz fuzz fuzz 0.6 and earlier creates temporary files insecurely, which could allow local users to gain root privileges. NVD-CWE-Other
CVE-2003-0261 2008-09-11 04:18 2003-05-27 表示 GitHub Exploit DB Packet Storm
312464 7.5 HIGH
apple
kde
redhat
turbolinux
safari
konqueror_embedded
kde
linux
turbolinux_server
turbolinux_workstation
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle atta… NVD-CWE-Other
CVE-2003-0370 2008-09-11 04:18 2003-06-16 表示 GitHub Exploit DB Packet Storm
312465 5.0 MEDIUM
apple darwin_streaming_server Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via a request to view_broadcast.cgi that does not contain the required parameters. NVD-CWE-Other
CVE-2003-0422 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312466 5.0 MEDIUM
apple darwin_streaming_server parse_xml.cgi in Apple QuickTime / Darwin Streaming Server before 4.1.3g allows remote attackers to obtain the source code for parseable files via the filename parameter. NVD-CWE-Other
CVE-2003-0423 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312467 5.0 MEDIUM
apple darwin_streaming_server Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to obtain the source code for scripts by appending encoded space (%20) or . (%2e) characters to an HTTP request for the… NVD-CWE-Other
CVE-2003-0424 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312468 5.0 MEDIUM
apple darwin_streaming_server Directory traversal vulnerability in Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to read arbitrary files via a ... (triple dot) in an HTTP request. NVD-CWE-Other
CVE-2003-0425 2008-09-11 04:18 2003-08-27 表示 GitHub Exploit DB Packet Storm
312469 7.2 HIGH
apc apcupsd Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.x before 3.10.5, may allow attackers to cause a denial of service or execute arbitrary code, related to usage of the vsprintf function. NVD-CWE-Other
CVE-2003-0099 2008-09-11 04:17 2003-03-3 表示 GitHub Exploit DB Packet Storm
312470 1.2 LOW
jmcce
mandrakesoft
jmcce
mandrake_linux
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NVD-CWE-Other
CVE-2002-2001 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312471 7.2 HIGH
qnx rtos Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-… NVD-CWE-Other
CVE-2002-2041 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312472 7.5 HIGH
mozilla
netscape
mozilla
navigator
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values… NVD-CWE-Other
CVE-2002-2061 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312473 7.5 HIGH
bea weblogic_server BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Se… NVD-CWE-Other
CVE-2002-2141 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312474 7.5 HIGH
bea weblogic_integration
weblogic_server
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through … NVD-CWE-Other
CVE-2002-2142 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312475 4.3 MEDIUM
andrey_cherezov acweb Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web script via a URL, possibly via a "%db" request in a URL. NVD-CWE-Other
CVE-2002-2171 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312476 2.6 LOW
bea weblogic_server BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to … NVD-CWE-Other
CVE-2002-2177 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312477 7.5 HIGH
benjamin_lefevre dobermann_forum Benjamin Lefevre Dobermann FORUM 0.5 and earlier allows remote attackers to remotely include and execute malicious PHP files via the "subpath" variablein (1) entete.php, (2) enteteacceuil.php, (3) in… NVD-CWE-Other
CVE-2002-2200 2008-09-11 04:16 2002-12-31 表示 GitHub Exploit DB Packet Storm
312478 5.0 MEDIUM
mike_spice my_classifieds Directory traversal vulnerability in Mike Spice's My Classifieds (classifieds.cgi) before 1.3 allows remote attackers to overwrite arbitrary files via the category parameter. NVD-CWE-Other
CVE-2002-1600 2008-09-11 04:15 2002-01-9 表示 GitHub Exploit DB Packet Storm
312479 5.0 MEDIUM
mywebserver mywebserver MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request, possibly triggering a buffer overflow. NVD-CWE-Other
CVE-2002-1897 2008-09-11 04:15 2002-12-31 表示 GitHub Exploit DB Packet Storm
312480 5.0 MEDIUM
ibm websphere_caching_proxy_server IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version nu… NVD-CWE-Other
CVE-2002-1169 2008-09-11 04:14 2002-11-4 表示 GitHub Exploit DB Packet Storm
312481 4.6 MEDIUM
cisco unity_server The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international cal… NVD-CWE-Other
CVE-2002-1189 2008-09-11 04:14 2002-10-11 表示 GitHub Exploit DB Packet Storm
312482 2.1 LOW
tkmail tkmail tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files. NVD-CWE-Other
CVE-2002-1193 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312483 7.5 HIGH
netbsd netbsd Buffer overflow in talkd on NetBSD 1.6 and earlier, and possibly other operating systems, may allow remote attackers to execute arbitrary code via a long inbound message. NVD-CWE-Other
CVE-2002-1194 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312484 7.5 HIGH
compaq tru64 Unknown vulnerability in routed for HP Tru64 UNIX V4.0F through V5.1A allows local and remote attackers to read arbitrary files. NVD-CWE-Other
CVE-2002-1202 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312485 5.0 MEDIUM
netscape communicator Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail passwo… NVD-CWE-Other
CVE-2002-1204 2008-09-11 04:14 2002-11-29 表示 GitHub Exploit DB Packet Storm
312486 5.0 MEDIUM
radiobird_software webserver_4_all Buffer overflow in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to cause a denial of service (crash) via a long HTTP GET request. NVD-CWE-Other
CVE-2002-1212 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312487 5.0 MEDIUM
radiobird_software webserver_4_all Directory traversal vulnerability in RadioBird Software WebServer 4 Everyone 1.23 and 1.27, and other versions before 1.30, allows remote attackers to read arbitrary files via an HTTP request with ".… NVD-CWE-Other
CVE-2002-1213 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312488 10.0 HIGH
linux-ha heartbeat Multiple format string vulnerabilities in heartbeat 0.4.9 and earlier (claimed as buffer overflows in some sources) allow remote attackers to execute arbitrary code via certain packets to UDP port 69… NVD-CWE-Other
CVE-2002-1215 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312489 7.1 HIGH
cisco catos Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote attackers to cause a denial of service (reset) via a long HTTP request. CWE-119
バッファエラー
CVE-2002-1222 2008-09-11 04:14 2002-10-28 表示 GitHub Exploit DB Packet Storm
312490 2.1 LOW
caldera unixware
openunix
SCO UnixWare 7.1.1 and Open UNIX 8.0.0 allows local users to cause a denial of service via an rcp call on /proc. NVD-CWE-Other
CVE-2002-1231 2008-09-11 04:14 2002-11-4 表示 GitHub Exploit DB Packet Storm
312491 7.2 HIGH
abuse abuse Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argument. NVD-CWE-Other
CVE-2002-1250 2008-09-11 04:14 2002-11-12 表示 GitHub Exploit DB Packet Storm
312492 5.0 MEDIUM
peoplesoft peopletools The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External Entities (XXE) fie… NVD-CWE-Other
CVE-2002-1252 2008-09-11 04:14 2003-02-7 表示 GitHub Exploit DB Packet Storm
312493 7.5 HIGH
jacques_gelinas linuxconf The mailconf module in Linuxconf 1.24, and other versions before 1.28, on Conectiva Linux 6.0 through 8, and possibly other distributions, generates the Sendmail configuration file (sendmail.cf) in a… NVD-CWE-Other
CVE-2002-1278 2008-09-11 04:14 2002-11-12 表示 GitHub Exploit DB Packet Storm
312494 7.2 HIGH
masqmail masqmail Multiple buffer overflows in conf.c for Masqmail 0.1.x before 0.1.17, and 0.2.x before 0.2.15, allow local users to gain privileges via certain entries in the configuration file (-C option). NVD-CWE-Other
CVE-2002-1279 2008-09-11 04:14 2002-11-29 表示 GitHub Exploit DB Packet Storm
312495 5.0 MEDIUM
iss realsecure_event_collector Memory leak in RealSecure Event Collector 6.5 allows attackers to cause a denial of service (memory consumption and crash). NVD-CWE-Other
CVE-2002-1280 2008-09-11 04:14 2002-05-17 表示 GitHub Exploit DB Packet Storm
312496 7.2 HIGH
suse suse_linux runlpr in the LPRng package allows the local lp user to gain root privileges via certain command line arguments. NVD-CWE-Other
CVE-2002-1285 2008-09-11 04:14 2002-11-29 表示 GitHub Exploit DB Packet Storm
312497 7.5 HIGH
smb2www smb2www Unknown vulnerability in smb2www 980804-16 and earlier allows remote attackers to execute arbitrary commands. NVD-CWE-Other
CVE-2002-1342 2008-09-11 04:14 2002-12-18 表示 GitHub Exploit DB Packet Storm
312498 5.0 MEDIUM
per_magne_knutsen cartman Per Magne Knutsen's CartMan shopping cart (cartman.php) 1.04 and earlier allows remote attackers to modify product prices by changing the price parameter. NVD-CWE-Other
CVE-2002-1352 2008-09-11 04:14 2003-09-17 表示 GitHub Exploit DB Packet Storm
312499 7.5 HIGH
openldap openldap OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows remote or local attackers to execute arbitrary code when libldap reads the .ldaprc file within applications that are running with extra privileges. NVD-CWE-Other
CVE-2002-1379 2008-09-11 04:14 2003-01-2 表示 GitHub Exploit DB Packet Storm
312500 2.1 LOW
debian internet_message Internet Message (IM) 141-18 and earlier uses predictable file and directory names, which allows local users to (1) obtain unauthorized directory permissions via a temporary directory used by impwage… NVD-CWE-Other
CVE-2002-1395 2008-09-11 04:14 2003-01-17 表示 GitHub Exploit DB Packet Storm