Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown
CVE-2018-18688
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.
0
Attacker Value
Unknown
CVE-2017-12969
Disclosure Date: November 10, 2017 (last updated November 08, 2023)
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.
0
Attacker Value
Unknown
CVE-2017-10857
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
0
Attacker Value
Unknown
CVE-2017-2116
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-2115
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4872
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
0
Attacker Value
Unknown
CVE-2016-4867
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
0
Attacker Value
Unknown
CVE-2016-4869
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
0
Attacker Value
Unknown
CVE-2016-4865
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
0
Attacker Value
Unknown
CVE-2016-4871
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
0