Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Office
(Cybozu)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 71 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-04-17 | CVE-2016-4873 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function. | Office | 4.3 | ||
2017-04-17 | CVE-2016-4872 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail. | Office | 4.3 | ||
2017-04-17 | CVE-2016-4871 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service. | Office | 6.5 | ||
2017-04-17 | CVE-2016-4870 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function. | Office | 5.4 | ||
2017-04-17 | CVE-2016-4869 | Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed. | Office | 6.5 | ||
2017-04-17 | CVE-2016-4868 | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests. | Office | 4.3 | ||
2017-04-17 | CVE-2016-4867 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. | Office | 4.3 | ||
2017-04-17 | CVE-2016-4866 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function. | Office | 4.8 | ||
2017-04-17 | CVE-2016-4865 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function. | Office | 4.8 | ||
2016-02-17 | CVE-2016-1153 | customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489. | Office | 6.5 |