CVE-2016-4842
https://notcve.org/view.php?id=CVE-2016-4842
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. Cybozu Mailwise en versiones anteriores a 5.4.0 permite a atacantes remotos obtener información cuando un email es leído. • http://jvn.jp/en/jp/JVN02576342/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000136.html http://www.securityfocus.com/bid/92460 https://support.cybozu.com/ja-jp/article/9606 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-1219
https://notcve.org/view.php?id=CVE-2016-1219
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use. Cybozu Garoon en versiones anteriores a 4.2.2 permite a atacantes remotos eludir la autenticación de acceso a través de vectores relacionados con el uso de API. • http://jvn.jp/en/jp/JVN89211736/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000148.html http://www.securityfocus.com/bid/92598 https://support.cybozu.com/ja-jp/article/9408 • CWE-287: Improper Authentication •
CVE-2016-4870
https://notcve.org/view.php?id=CVE-2016-4870
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function. Una vulnerabilidad de tipo cross-site scripting en Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes autenticados remotos inyectar script web o HTML arbitrario por medio de la función Schedule. • http://jvn.jp/en/jp/JVN06726266/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000186.html http://www.securityfocus.com/bid/93281 https://support.cybozu.com/ja-jp/article/9427 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2016-4867
https://notcve.org/view.php?id=CVE-2016-4867
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes autenticados remotos omitir la restricción de acceso para visualizar información del proyecto no autorizada por medio de la función Project. • http://jvn.jp/en/jp/JVN07148816/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000187.html http://www.securityfocus.com/bid/93461 https://support.cybozu.com/ja-jp/article/9429 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2016-4866
https://notcve.org/view.php?id=CVE-2016-4866
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function. Una vulnerabilidad de tipo cross-site scripting en Cybozu Office versiones 9.0.0 hasta 10.4.0, permite a los atacantes con derechos de administrador inyectar script web o HTML arbitrario por medio de la función Project. • http://jvn.jp/en/jp/JVN06726266/index.html http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000185.html http://www.securityfocus.com/bid/93281 https://support.cybozu.com/ja-jp/article/9431 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •