CVE-2016-4865
- EPSS 0.4%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
CVE-2016-4866
- EPSS 0.4%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
CVE-2016-4867
- EPSS 0.22%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
CVE-2016-4868
- EPSS 0.67%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
CVE-2016-4869
- EPSS 1.16%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
CVE-2016-4871
- EPSS 1.51%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
CVE-2016-4872
- EPSS 0.22%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
CVE-2016-4873
- EPSS 0.28%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
CVE-2016-4874
- EPSS 0.23%
- Veröffentlicht 17.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
CVE-2016-1153
- EPSS 0.58%
- Veröffentlicht 17.02.2016 02:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.