NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2026年6月22日4:00

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
349201 4.0 MEDIUM
plaino wimpy_mp3 wimpy_trackplays.php in Plaino Wimpy MP3 Player, possibly 5.2 and earlier, allows remote attackers to insert arbitrary strings into trackme.txt via the (1) trackFile, (2) trackArtist, and (3) trackTi… NVD-CWE-Other
CVE-2006-0787 2017-07-20 10:30 2006-02-19 表示 GitHub Exploit DB Packet Storm
349202 5.0 MEDIUM
kyocera fs-3830n Kyocera 3830 (aka FS-3830N) printers have a back door that allows remote attackers to read and alter configuration settings via strings that begin with "!R!SIOP0", as demonstrated using (1) a connect… NVD-CWE-Other
CVE-2006-0788 2017-07-20 10:30 2006-02-19 表示 GitHub Exploit DB Packet Storm
349203 10.0 HIGH
kyocera fs-3830n Certain unspecified Kyocera printers have a default "admin" account with a blank password, which allows remote attackers to access an administrative menu via a telnet session. NVD-CWE-Other
CVE-2006-0789 2017-07-20 10:30 2006-02-19 表示 GitHub Exploit DB Packet Storm
349204 5.0 MEDIUM
rockliffe mailsite Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsuite. NVD-CWE-Other
CVE-2006-0790 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349205 4.3 MEDIUM
v-webmail v-webmail Cross-site scripting (XSS) vulnerability in preferences.personal.php in V-webmail 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the newid parameter. NOTE: the provenance o… NVD-CWE-Other
CVE-2006-0792 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349206 5.0 MEDIUM
v-webmail v-webmail frameset.php in V-webmail 1.6.2 allows remote attackers to conduct phishing attacks by referencing arbitrary websites in the rframe parameter. NOTE: the provenance of this information is unknown; th… NVD-CWE-Other
CVE-2006-0793 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349207 5.0 MEDIUM
v-webmail v-webmail help.php in V-webmail 1.6.2 allows remote attackers to obtain the installation path via unspecified invalid parameters. NOTE: the provenance of this information is unknown; the details are obtained … NVD-CWE-Other
CVE-2006-0794 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349208 4.3 MEDIUM
clever_copy clever_copy Cross-site scripting (XSS) vulnerability in default.php in Clever Copy 3.0 allows remote attackers to inject arbitrary web script or HTML via the Subject field when sending private messages (privatem… NVD-CWE-Other
CVE-2006-0796 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349209 7.8 HIGH
nokia n70 Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2… NVD-CWE-Other
CVE-2006-0797 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349210 5.5 MEDIUM
macallan mail_solution Multiple directory traversal vulnerabilities in the IMAP service in Macallan Mail Solution before 4.8.05.004 allow remote authenticated users to read e-mails of other users or create, modify, or dele… NVD-CWE-Other
CVE-2006-0798 2017-07-20 10:30 2006-02-20 表示 GitHub Exploit DB Packet Storm
349211 2.6 LOW
postnuke_software_foundation postnuke Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" … CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-0800 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349212 5.1 MEDIUM
postnuke_software_foundation postnuke SQL injection vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is off, allows remote attackers to execute arbitrary SQL commands via the language paramet… NVD-CWE-Other
CVE-2006-0801 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349213 5.1 MEDIUM
postnuke_software_foundation postnuke Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled. NVD-CWE-Other
CVE-2006-0801 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349214 2.6 LOW
postnuke_software_foundation postnuke Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML vi… NVD-CWE-Other
CVE-2006-0802 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349215 2.6 LOW
postnuke_software_foundation postnuke Successful exploitation requires that the "magic_quotes_gpc" parameter is disabled. NVD-CWE-Other
CVE-2006-0802 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349216 7.5 HIGH
tin tin Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow. NVD-CWE-Other
CVE-2006-0804 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349217 6.4 MEDIUM
mute mute MUTE 0.4 allows remote attackers to cause a denial of service (messages not forwarded) and obtain sensitive information about a target by filling a client's mWebCache cache with malicious "zombie" no… NVD-CWE-Other
CVE-2006-0808 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349218 7.5 HIGH
skate_board skate_board Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd pa… NVD-CWE-Other
CVE-2006-0809 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349219 3.5 LOW
skate_board skate_board Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly… NVD-CWE-Other
CVE-2006-0810 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349220 4.3 MEDIUM
skate_board skate_board Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration for… NVD-CWE-Other
CVE-2006-0811 2017-07-20 10:30 2006-02-21 表示 GitHub Exploit DB Packet Storm
349221 5.0 MEDIUM
emulinker_kaillera_server emulinker_kaillera_server Unspecified vulnerability in EmuLinker Kaillera Server before 0.99.17 allows remote attackers to cause a denial of service (probably resource consumption) via a crafted packet that causes a "ghost ga… NVD-CWE-Other
CVE-2006-0822 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349222 7.5 HIGH
xerox workcentre_232
workcentre_238
workcentre_245
workcentre_255
workcentre_265
workcentre_275
Multiple unspecified vulnerabilities in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allow remote a… NVD-CWE-Other
CVE-2006-0825 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349223 5.0 MEDIUM
xerox workcentre_232
workcentre_238
workcentre_245
workcentre_255
workcentre_265
workcentre_275
Unspecified vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote attackers t… NVD-CWE-Other
CVE-2006-0826 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349224 5.0 MEDIUM
xerox workcentre_232
workcentre_238
workcentre_245
workcentre_255
workcentre_265
workcentre_275
Cross-site scripting vulnerability in ESS/ Network Controller and MicroServer Web Server in Xerox WorkCentre Pro and Xerox WorkCentre running software 13.027.24.015 and 14.027.24.015 allows remote at… NVD-CWE-Other
CVE-2006-0827 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349225 4.3 MEDIUM
boonex barracuda_directory Multiple cross-site scripting (XSS) vulnerabilities in Barracuda Directory 1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) Add URL and (2) Suggest… NVD-CWE-Other
CVE-2006-0833 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349226 7.5 HIGH
mitridat web_calendar_pro SQL injection vulnerability in dropbase.php in MitriDAT Web Calendar Pro allows remote attackers to modify internal SQL queries and cause a denial of service (inaccessible database) via the tabls par… NVD-CWE-Other
CVE-2006-0835 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349227 4.3 MEDIUM
calacode atmail_webmail_system Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute of an IMG element … CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-0842 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349228 4.3 MEDIUM
calacode atmail_webmail_system Successful exploitation of this issue requires a victim user has @Mail configured to display images in email messages. CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2006-0842 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349229 5.0 MEDIUM
leif_m._wright web_blog Leif M. Wright's Blog 3.5 stores the config file and other txt files under the web root with insufficient access control, which allows remote attackers to read the administrator's password. NVD-CWE-Other
CVE-2006-0843 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349230 7.5 HIGH
leif_m._wright web_blog Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the … NVD-CWE-Other
CVE-2006-0844 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349231 6.5 MEDIUM
leif_m._wright web_blog Leif M. Wright's Blog 3.5 allows remote authenticated users with administrative privileges to execute arbitrary programs, including shell commands, by configuring the sendmail path to a malicious pat… NVD-CWE-Other
CVE-2006-0845 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349232 4.3 MEDIUM
leif_m._wright web_blog Multiple cross-site scripting (XSS) vulnerabilities in Leif M. Wright's Blog 3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Referer and (2) User-Agent HTTP headers, whi… NVD-CWE-Other
CVE-2006-0846 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349233 5.0 MEDIUM
cherrypy cherrypy Directory traversal vulnerability in the staticfilter component in CherryPy before 2.1.1 allows remote attackers to read arbitrary files via ".." sequences in unspecified vectors. NVD-CWE-Other
CVE-2006-0847 2017-07-20 10:30 2006-02-22 表示 GitHub Exploit DB Packet Storm
349234 5.1 MEDIUM
apple mac_os_x
mac_os_x_server
The "Open 'safe' files after downloading" option in Safari on Apple Mac OS X allows remote user-assisted attackers to execute arbitrary commands by tricking a user into downloading a __MACOSX folder … CWE-16
環境設定
CVE-2006-0848 2017-07-20 10:30 2006-02-23 表示 GitHub Exploit DB Packet Storm
349235 7.5 HIGH
ilch.de ilchclan SQL injection vulnerability in include/includes/user/login.php in ilchClan before 1.05g allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance o… NVD-CWE-Other
CVE-2006-0850 2017-07-20 10:30 2006-02-23 表示 GitHub Exploit DB Packet Storm
349236 7.5 HIGH
intensive_point iuser_ecommerce PHP remote file inclusion vulnerability in common.php in Intensive Point iUser Ecommerce allows remote attackers to include arbitrary files via a URL in the include_path variable, which is not initia… CWE-94
コード・インジェクション
CVE-2006-0854 2017-07-20 10:30 2006-02-23 表示 GitHub Exploit DB Packet Storm
349237 5.0 MEDIUM
coppermine coppermine_photo_gallery Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) … NVD-CWE-Other
CVE-2006-0872 2017-07-20 10:30 2006-02-24 表示 GitHub Exploit DB Packet Storm
349238 5.0 MEDIUM
coppermine coppermine_photo_gallery Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote fi… NVD-CWE-Other
CVE-2006-0873 2017-07-20 10:30 2006-02-24 表示 GitHub Exploit DB Packet Storm
349239 5.0 MEDIUM
openbsd
freebsd
openssh
freebsd
OpenSSH on FreeBSD 5.3 and 5.4, when used with OpenPAM, does not properly handle when a forked child process terminates during PAM authentication, which allows remote attackers to cause a denial of s… CWE-399
リソース管理の問題
CVE-2006-0883 2017-07-20 10:30 2006-03-7 表示 GitHub Exploit DB Packet Storm
349240 4.3 MEDIUM
cutephp cutenews Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter. NVD-CWE-Other
CVE-2006-0885 2017-07-20 10:30 2006-02-25 表示 GitHub Exploit DB Packet Storm
349241 4.3 MEDIUM
dev dev_web_management_system Cross-site scripting (XSS) vulnerability in register.php in DEV web management system 1.5 allows remote attackers to inject arbitrary web script or HTML via the "City/Region" field (mesto variable). … NVD-CWE-Other
CVE-2006-0886 2017-07-20 10:30 2006-02-25 表示 GitHub Exploit DB Packet Storm
349242 7.5 HIGH
phplib_team phplib Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbi… CWE-94
コード・インジェクション
CVE-2006-0887 2017-07-20 10:30 2006-02-25 表示 GitHub Exploit DB Packet Storm
349243 4.3 MEDIUM
brown_bear_software calcium Cross-site scripting (XSS) vulnerability in Calcium 3.10.1 allows remote attackers to inject arbitrary web script or HTML via the EventText parameter. NOTE: the provenance of this information is unk… NVD-CWE-Other
CVE-2006-0889 2017-07-20 10:30 2006-02-25 表示 GitHub Exploit DB Packet Storm
349244 5.0 MEDIUM
nocc nocc Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_… NVD-CWE-Other
CVE-2006-0891 2017-07-20 10:30 2006-02-25 表示 GitHub Exploit DB Packet Storm
349245 7.8 HIGH
freebsd freebsd nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite. NVD-CWE-Other
CVE-2006-0900 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349246 7.5 HIGH
freebsd
netbsd
freebsd
netbsd
A "programming error" in fast_ipsec in FreeBSD 4.8-RELEASE through 6.1-STABLE and NetBSD 2 through 3 does not properly update the sequence number associated with a Security Association, which allows … NVD-CWE-Other
CVE-2006-0905 2017-07-20 10:30 2006-03-23 表示 GitHub Exploit DB Packet Storm
349247 4.3 MEDIUM
brown_bear_software ical Cross-site scripting (XSS) vulnerability in Brown Bear iCal 3.10 allows remote attackers to inject arbitrary web script or HTML via the Calendar Text field when a new event is added. NOTE: the prove… NVD-CWE-Other
CVE-2006-0924 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349248 4.3 MEDIUM
brown_bear_software ical This vulnerability affects Brown Bear iCal version 3.10 and previous. NVD-CWE-Other
CVE-2006-0924 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349249 5.0 MEDIUM
alt-n mdaemon Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folde… NVD-CWE-Other
CVE-2006-0925 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm
349250 4.3 MEDIUM
phpx phpx Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message. NOTE: the provenanc… NVD-CWE-Other
CVE-2006-0933 2017-07-20 10:30 2006-02-28 表示 GitHub Exploit DB Packet Storm