CVE-2018-0565
- EPSS 0.24%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:29
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0529
- EPSS 0.39%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2018-0528
- EPSS 0.18%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.
CVE-2018-0527
- EPSS 0.24%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:24
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0526
- EPSS 0.26%
- Veröffentlicht 26.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:24
Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors.
CVE-2017-10857
- EPSS 0.14%
- Veröffentlicht 12.10.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
CVE-2017-2116
- EPSS 0.2%
- Veröffentlicht 28.04.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
CVE-2017-2115
- EPSS 0.13%
- Veröffentlicht 28.04.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
CVE-2017-2114
- EPSS 0.18%
- Veröffentlicht 28.04.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-4870
- EPSS 0.28%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.