Office
by Cybozu
CVEs (78)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-1151 | Hig | 0.57 | 8.8 | 0.01 | Feb 17, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users. | ||
| CVE-2018-0704 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen. | ||
| CVE-2018-0703 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2019 | Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests. | ||
| CVE-2015-8483 | Hig | 0.48 | 7.4 | 0.01 | Feb 17, 2016 | Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | ||
| CVE-2024-39817 | Med | 0.42 | 6.5 | 0.00 | Aug 6, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App. | ||
| CVE-2022-32453 | Med | 0.42 | 6.5 | 0.01 | Aug 18, 2022 | HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors. | ||
| CVE-2021-20631 | Med | 0.42 | 6.5 | 0.01 | Mar 18, 2021 | Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors. | ||
| CVE-2021-20626 | Med | 0.42 | 6.5 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via unspecified vectors. | ||
| CVE-2021-20624 | Med | 0.42 | 6.5 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Scheduler via unspecified vectors. | ||
| CVE-2019-6022 | Med | 0.42 | 6.5 | 0.02 | Dec 26, 2019 | Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function. | ||
| CVE-2016-4871 | Med | 0.42 | 6.5 | 0.02 | Apr 17, 2017 | Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service. | ||
| CVE-2016-4869 | Med | 0.42 | 6.5 | 0.02 | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed. | ||
| CVE-2016-1153 | Med | 0.42 | 6.5 | 0.02 | Feb 17, 2016 | customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489. | ||
| CVE-2015-8489 | Med | 0.42 | 6.5 | 0.02 | Feb 17, 2016 | customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153. | ||
| CVE-2018-0567 | Med | 0.41 | 6.3 | 0.01 | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass access restriction to access and write non-public data via unspecified vectors. | ||
| CVE-2022-33151 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2022 | Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors. | ||
| CVE-2022-30604 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2022 | Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | ||
| CVE-2022-29487 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2022 | Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | ||
| CVE-2022-28715 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2022 | Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors. | ||
| CVE-2021-20629 | Med | 0.40 | 6.1 | 0.01 | Mar 18, 2021 | Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. |
- risk 0.57cvss 8.8epss 0.01
Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.
- risk 0.49cvss 7.5epss 0.02
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.
- risk 0.48cvss 7.4epss 0.01
Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
- risk 0.42cvss 6.5epss 0.00
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
- risk 0.42cvss 6.5epss 0.01
HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Scheduler via unspecified vectors.
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to alter arbitrary files via the 'Customapp' function.
- risk 0.42cvss 6.5epss 0.02
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
- risk 0.42cvss 6.5epss 0.02
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.
- risk 0.42cvss 6.5epss 0.02
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.
- risk 0.42cvss 6.5epss 0.02
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.
- risk 0.41cvss 6.3epss 0.01
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass access restriction to access and write non-public data via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers to inject an arbitrary script via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary script via unspecified vectors.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.
Page 1 of 4