Show filters
30 Total Results
Displaying 11-20 of 30
Sort by:
Attacker Value
Unknown

CVE-2016-4874

Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
0
Attacker Value
Unknown

CVE-2016-4873

Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
0
Attacker Value
Unknown

CVE-2016-4870

Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
0
Attacker Value
Unknown

CVE-2016-4868

Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
0
Attacker Value
Unknown

CVE-2015-8484

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.
0
Attacker Value
Unknown

CVE-2015-7796

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
0
Attacker Value
Unknown

CVE-2015-8486

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.
0
Attacker Value
Unknown

CVE-2015-7795

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.
0
Attacker Value
Unknown

CVE-2015-8487

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
0
Attacker Value
Unknown

CVE-2015-7798

Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2016-1149, and CVE-2016-1150.
0