CVE-2021-20799
- EPSS 0.21%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20797
- EPSS 0.21%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cross-site script inclusion vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to obtain the information stored in the product. This issue occurs only when using Mozilla Firefox.
CVE-2021-20796
- EPSS 0.43%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated attacker to upload an arbitrary file via unspecified vectors.
CVE-2021-20795
- EPSS 0.09%
- Veröffentlicht 13.10.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 05:47:12
Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vector...
CVE-2018-16172
- EPSS 0.1%
- Veröffentlicht 09.01.2019 23:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:13
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
CVE-2018-16171
- EPSS 1.05%
- Veröffentlicht 09.01.2019 23:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:13
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
CVE-2018-16170
- EPSS 0.6%
- Veröffentlicht 09.01.2019 23:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:12
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
CVE-2018-16169
- EPSS 0.85%
- Veröffentlicht 09.01.2019 23:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:12
Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.
CVE-2016-7815
- EPSS 0.09%
- Veröffentlicht 28.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.
CVE-2014-7266
- EPSS 0.55%
- Veröffentlicht 01.02.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerabi...