![](/assets/img/cve_300x82_sin_bg.png)
CVE-2023-36565 – Microsoft Office Graphics Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2023-36565
10 Oct 2023 — Microsoft Office Graphics Elevation of Privilege Vulnerability Vulnerabilidad de elevación de privilegios en Microsoft Office Graphics • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36565 • CWE-416: Use After Free •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2021-43905 – Microsoft Office app Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-43905
15 Dec 2021 — Microsoft Office app Remote Code Execution Vulnerability Una vulnerabilidad de Ejecución de Código Remota en Microsoft Office app • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-43905 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2019-11828
https://notcve.org/view.php?id=CVE-2019-11828
30 Jun 2019 — Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Una vulnerabilidad de tipo cross-site-scripting (XSS) en Chart en Synology Office anterior a versión 3.1.4-2771, permite a los usuarios autenticados remotos inyectar script web o HTML arbitrario por medio de vectores no especificados. • https://www.synology.com/security/advisory/Synology_SA_19_11 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-8924
https://notcve.org/view.php?id=CVE-2018-8924
05 Jun 2018 — Cross-site scripting (XSS) vulnerability in Title Tootip in Synology Office before 3.0.3-2143 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name. Vulnerabilidad de Cross-Site Scripting (XSS) en Title Tootip en Synology Office en versiones anteriores a la 3.0.3-2143 permite que usuarios remotos autenticados inyecten scripts web o HTML arbitrarios mediante un nombre de archivo malicioso. • https://www.synology.com/zh-tw/support/security/Synology_SA_18_12 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-11150
https://notcve.org/view.php?id=CVE-2017-11150
14 Aug 2017 — Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents. Una vulnerabilidad de inyección de comandos en Document.php en Synology Office 2.2.0-1502 y 2.2.1-1506 permite que usuarios remotos autenticados ejecuten comandos arbitrarios mediante metacaracteres shell en el nombre del archivo manipulado de documentos RTF. • https://www.synology.com/en-global/support/security/Synology_SA_17_26_Office • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-5314
https://notcve.org/view.php?id=CVE-2014-5314
24 Nov 2014 — Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-mail messages. Desbordamiento de buffer en Cybozu Office 9 y 10 anterior a 10.1.0, Mailwise 4 y 5 anterior a 5.1.4, y Dezie 8 anterior a 8.1.1 permite a usuarios remotos autenticados ejecutar código arbitrario a través de mensajes de email. • http://jvn.jp/en/jp/JVN14691234/index.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2013-4703
https://notcve.org/view.php?id=CVE-2013-4703
10 Sep 2013 — Cross-site scripting (XSS) vulnerability in the top-page customization feature in Cybozu Office before 9.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de cross-site scripting (XSS) en la funcionalidad de personalización de página superior en Cybozu Office anteriores a 9.3.1 permite a atacantes remotos inyectar scripts web o HTML arbitrarios a través de vectores no especificados. • http://cs.cybozu.co.jp/information/20130909up11.php • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2011-2677
https://notcve.org/view.php?id=CVE-2011-2677
21 Oct 2011 — Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to manipulation of a URL. Cybozu de Office anteriores a v8.0.0 permite a usuarios remotos autenticados a eludir las restricciones de acceso y acceder a la información confidencial a través de vectores no especificados relacionados con la manipulación de una URL. • http://cs.cybozu.co.jp/information/20111005notice01.php • CWE-264: Permissions, Privileges, and Access Controls •