Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2021-45105
Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
0
Attacker Value
Unknown
CVE-2019-10086
Disclosure Date: August 20, 2019 (last updated November 08, 2023)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
0
Attacker Value
Unknown
CVE-2017-10857
Disclosure Date: October 12, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
0
Attacker Value
Unknown
CVE-2017-2114
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-2116
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-2115
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4872
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
0
Attacker Value
Unknown
CVE-2016-4867
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
0
Attacker Value
Unknown
CVE-2016-4869
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
0
Attacker Value
Unknown
CVE-2016-4871
Disclosure Date: April 17, 2017 (last updated November 26, 2024)
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
0