Page 42 of 318 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 14EXPL: 0

Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. Cybozu Mailwise en versiones anteriores a 5.4.0 permite a atacantes remotos obtener información cuando un email es leído. • http://jvn.jp/en/jp/JVN02576342/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000136.html http://www.securityfocus.com/bid/92460 https://support.cybozu.com/ja-jp/article/9606 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000148.html http://www.securityfocus.com/bid/92598 https://support.cybozu.com/ja-jp/article/9408 • CWE-287: Improper Authentication •

CVSS: 5.4EPSS: 0%CPEs: 16EXPL: 0

Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function. Una vulnerabilidad de tipo cross-site scripting en Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes autenticados remotos inyectar script web o HTML arbitrario por medio de la función Schedule. • http://jvn.jp/en/jp/JVN06726266/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000186.html http://www.securityfocus.com/bid/93281 https://support.cybozu.com/ja-jp/article/9427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 16EXPL: 0

Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes autenticados remotos omitir la restricción de acceso para visualizar información del proyecto no autorizada por medio de la función Project. • http://jvn.jp/en/jp/JVN07148816/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000187.html http://www.securityfocus.com/bid/93461 https://support.cybozu.com/ja-jp/article/9429 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.8EPSS: 0%CPEs: 16EXPL: 0

Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function. Una vulnerabilidad de tipo cross-site scripting en Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes con derechos de administrador inyectar script web o HTML arbitrario por medio de la función Project. • http://jvn.jp/en/jp/JVN06726266/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000185.html http://www.securityfocus.com/bid/93281 https://support.cybozu.com/ja-jp/article/9431 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •