NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2026年6月10日5:00

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
350151 7.5 HIGH
sandsurfer sandsurfer Unknown vulnerability in SandSurfer before 1.7.0 allows remote attackers to gain access as a logged-in user. NVD-CWE-Other
CVE-2004-2087 2017-07-11 10:31 2004-02-8 表示 GitHub Exploit DB Packet Storm
350152 5.0 MEDIUM
sophos sophos_anti-virus Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message. NVD-CWE-Other
CVE-2004-2088 2017-07-11 10:31 2004-02-12 表示 GitHub Exploit DB Packet Storm
350153 5.0 MEDIUM
- - Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command. NVD-CWE-Other
CVE-2004-2089 2017-07-11 10:31 2004-02-6 表示 GitHub Exploit DB Packet Storm
350154 4.6 MEDIUM
- - Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PR… NVD-CWE-Other
CVE-2004-2093 2017-07-11 10:31 2004-02-9 表示 GitHub Exploit DB Packet Storm
350155 4.3 MEDIUM
darkwet webcam_xp Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web script as other users via a URL that contains the script. NVD-CWE-Other
CVE-2004-2094 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350156 5.0 MEDIUM
niels_provos honeyd Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd. NVD-CWE-Other
CVE-2004-2095 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350157 4.3 MEDIUM
mephistoles_internet_suite mephistoles_httpd Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL. NVD-CWE-Other
CVE-2004-2096 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350158 2.1 LOW
suse suse_linux Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/ra… NVD-CWE-Other
CVE-2004-2097 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350159 4.3 MEDIUM
native_solutions tbe_banner_engine Cross-site scripting (XSS) vulnerability in the banner engine (TBE) 5.0 allows remote attackers to execute arbitrary script as other users via the HTML banner view/preview capability. NVD-CWE-Other
CVE-2004-2098 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350160 5.1 MEDIUM
electronic_arts need_for_speed_hot_pursuit_2 Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostnam… NVD-CWE-Other
CVE-2004-2099 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350161 5.0 MEDIUM
geovision geohttpserver The sysinfo script in GeoHttpServer allows remote attackers to cause a denial of service (crash) via a long pwd parameter, possibly triggering a buffer overflow. NVD-CWE-Other
CVE-2004-2101 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350162 4.3 MEDIUM
- - Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. NVD-CWE-Other
CVE-2004-2102 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350163 7.5 HIGH
finjan_software surfingate Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which allows remote attackers to use the finjan-parameter-type header to (1) restart … NVD-CWE-Other
CVE-2004-2107 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350164 7.5 HIGH
quadcomm q-shop Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showc… NVD-CWE-Other
CVE-2004-2108 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350165 6.8 MEDIUM
quadcomm q-shop Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript… NVD-CWE-Other
CVE-2004-2109 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350166 5.0 MEDIUM
herberlin bremsserver Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in the URL. NVD-CWE-Other
CVE-2004-2112 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350167 4.3 MEDIUM
herberlin bremsserver Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the URL. NVD-CWE-Other
CVE-2004-2113 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350168 10.0 HIGH
internetnow proxynow Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL. NVD-CWE-Other
CVE-2004-2114 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350169 6.8 MEDIUM
oracle http_server Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attackers to execute arbitrary script as other users via the (1) action, (2) username, … NVD-CWE-Other
CVE-2004-2115 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350170 5.0 MEDIUM
reptile_web_server reptile_web_server Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version. NVD-CWE-Other
CVE-2004-2120 2017-07-11 10:31 2004-01-23 表示 GitHub Exploit DB Packet Storm
350171 5.0 MEDIUM
borland_software web_server_for_corel_paradox Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5… NVD-CWE-Other
CVE-2004-2121 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350172 4.3 MEDIUM
intra_forum intra_forum Cross-site scripting (XSS) vulnerability in intraforum_db.cgi in Intra Forum allows remote attackers to inject arbitrary web script or HTML via the (1) use_last_read or (2) forum parameters. NVD-CWE-Other
CVE-2004-2122 2017-07-11 10:31 2004-01-24 表示 GitHub Exploit DB Packet Storm
350173 4.3 MEDIUM
nextplace e-commerce_asp_engine Multiple cross-site scripting (XSS) vulnerabilities in Nextplace.com E-Commerce ASP Engine allow remote attackers to inject arbitrary web script or HTML via the (1) level parameter of productdetail.a… NVD-CWE-Other
CVE-2004-2123 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350174 5.0 MEDIUM
gallery_project gallery The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_… NVD-CWE-Other
CVE-2004-2124 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350175 4.6 MEDIUM
iss blackice_agent_server
blackice_pc_protection
blackice_server_protection
realsecure_desktop
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI fil… NVD-CWE-Other
CVE-2004-2125 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350176 5.0 MEDIUM
leif_m._wright web_blog Directory traversal vulnerability in Web Blog 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file variable. NVD-CWE-Other
CVE-2004-2127 2017-07-11 10:31 2004-01-20 表示 GitHub Exploit DB Packet Storm
350177 6.8 MEDIUM
- - Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as other users via the query string to ISAPISkeleton.dll. NVD-CWE-Other
CVE-2004-2128 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350178 5.0 MEDIUM
loom_software surfnow_professional
surfnow_standard
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow. NVD-CWE-Other
CVE-2004-2129 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350179 7.2 HIGH
ibm informix_dynamic_server
informix_extended_parallel_server
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment var… NVD-CWE-Other
CVE-2004-2131 2017-07-11 10:31 2004-01-27 表示 GitHub Exploit DB Packet Storm
350180 5.0 MEDIUM
pj_cgi_neo_review pj_cgi_neo_review Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NVD-CWE-Other
CVE-2004-2132 2017-07-11 10:31 2004-01-29 表示 GitHub Exploit DB Packet Storm
350181 4.6 MEDIUM
cvsup cvsup Certain third-party packages for CVSup 16.1h, such as SuSE Linux, contain untrusted paths in the ELF RPATH fields of certain executables, which could allow local users to execute arbitrary code by ca… NVD-CWE-Other
CVE-2004-2133 2017-07-11 10:31 2004-01-29 表示 GitHub Exploit DB Packet Storm
350182 5.0 MEDIUM
microsoft outlook_express Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fiel… NVD-CWE-Other
CVE-2004-2137 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350183 10.0 HIGH
jorg_schilling sdd Unknown vulnerability in the remote tape support (remote.c) in the RMT client for Jorg Schilling sdd 1.28 and 1.31 has unknown impact and attack vectors. NVD-CWE-Other
CVE-2004-2142 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350184 7.5 HIGH
mambo mambo_portal SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in th… NVD-CWE-Other
CVE-2004-2143 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350185 7.5 HIGH
pd9_software megabbs SQL injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows remote attackers to execute arbitrary SQL commands via the (1) sortdir or (2) criteria parameter to ladder-log.asp or the (3) memb… NVD-CWE-Other
CVE-2004-2145 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350186 5.0 MEDIUM
pd9_software megabbs CRLF injection vulnerability in PD9 Software MegaBBS 2 and 2.1 allows attackers to conduct HTTP response splitting attacks via the fid parameter in a writenew action to thread-post.asp. NVD-CWE-Other
CVE-2004-2146 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350187 7.2 HIGH
slava_astashonok fprobe Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors. NVD-CWE-Other
CVE-2004-2148 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350188 5.0 MEDIUM
virtual_projects chatman Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size. NVD-CWE-Other
CVE-2004-2151 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350189 4.3 MEDIUM
mediawiki mediawiki Cross-site scripting (XSS) vulnerability in 'raw' page output mode for MediaWiki 1.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML. NVD-CWE-Other
CVE-2004-2152 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350190 10.0 HIGH
real_estate_management_software real_estate_management_software Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors. NVD-CWE-Other
CVE-2004-2153 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350191 7.5 HIGH
- - Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6… NVD-CWE-Other
CVE-2004-2155 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350192 10.0 HIGH
recruitment_agency_software online_recruitment_agency Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors. NVD-CWE-Other
CVE-2004-2156 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350193 4.3 MEDIUM
s9y serendipity Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (… NVD-CWE-Other
CVE-2004-2157 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350194 7.5 HIGH
s9y serendipity SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php. NVD-CWE-Other
CVE-2004-2158 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350195 10.0 HIGH
xmlstarlet command_line_xml_toolkit Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c. NVD-CWE-Other
CVE-2004-2159 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350196 7.5 HIGH
tutos tutos SQL injection vulnerability in file_overview.php in TUTOS 1.1 allows remote attackers to execute arbitrary SQL commands via the link_id parameter. NVD-CWE-Other
CVE-2004-2161 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350197 4.3 MEDIUM
tutos tutos Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the search field of the Address Module or (2) the t parameter to… NVD-CWE-Other
CVE-2004-2162 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350198 7.5 HIGH
openbsd openbsd login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by sp… NVD-CWE-Other
CVE-2004-2163 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350199 5.0 MEDIUM
virtual_programming vp-asp shoprestoreorder.asp in VP-ASP 5.0 does not close the database connection when a user restores a previous order, which allows remote attackers to cause a denial of service (connection consumption). NVD-CWE-Other
CVE-2004-2164 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm
350200 5.0 MEDIUM
impressions_games lords_of_the_realm_iii Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname. NVD-CWE-Other
CVE-2004-2165 2017-07-11 10:31 2004-12-31 表示 GitHub Exploit DB Packet Storm