Show filters
101 Total Results
Displaying 51-60 of 101
Sort by:
Attacker Value
Unknown
CVE-2011-2677
Disclosure Date: October 21, 2011 (last updated October 04, 2023)
Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to manipulation of a URL.
0
Attacker Value
Unknown
CVE-2011-1334
Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the mail system."
0
Attacker Value
Unknown
CVE-2011-1335
Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user list functions."
0
Attacker Value
Unknown
CVE-2011-1333
Disclosure Date: June 29, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the bulletin board system."
0
Attacker Value
Unknown
CVE-2010-3452
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
0
Attacker Value
Unknown
CVE-2010-3450
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filter description file, (2) an Extension (aka OXT) file, or unspecified other (3) JAR or (4) ZIP files.
0
Attacker Value
Unknown
CVE-2010-3689
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
0
Attacker Value
Unknown
CVE-2010-4253
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file in an ODF or Microsoft Office document, as demonstrated by a PowerPoint (aka PPT) document.
0
Attacker Value
Unknown
CVE-2010-3453
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8 data in a Microsoft Word document, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .DOC file that triggers an out-of-bounds write.
0
Attacker Value
Unknown
CVE-2010-3454
Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
0