Vulnerabilities > Cybozu > Office > Low

DATE CVE VULNERABILITY TITLE RISK
2017-04-28 CVE-2017-2114 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
network
cybozu CWE-79
3.5
2017-04-17 CVE-2016-4865 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.
network
cybozu CWE-79
3.5
2017-04-17 CVE-2016-4866 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
network
cybozu CWE-79
3.5
2017-04-17 CVE-2016-4870 Cross-site Scripting vulnerability in Cybozu Office
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
network
cybozu CWE-79
3.5
2017-04-17 CVE-2016-4874 Improper Access Control vulnerability in Cybozu Office
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
network
cybozu CWE-284
3.5
2016-02-17 CVE-2015-8487 Information Exposure vulnerability in Cybozu Office
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.
network
high complexity
cybozu CWE-200
2.6