NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
10028 | CVE-2011-3376 | org/apache/catalina/core/DefaultInstanceManager.java in Apache Tomcat 7.x before 7.0.22 does not properly restrict ContainerServlets in the Manager application, which allows local users to gain privileges by using an untrusted web application to access the Manager application's functionality. | 2 | 4.4 | Medium | 2017-05-27 | 2017-05-22 | View | |
85306 | CVE-2016-4865 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-22 | View | |
85307 | CVE-2016-4866 | Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function. | 2 | 3.5 | Low | 2017-05-27 | 2017-05-22 | View | |
85308 | CVE-2016-4867 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. | 2 | 4 | Medium | 2017-05-27 | 2017-05-22 | View | |
85309 | CVE-2016-4868 | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests. | 2 | 4.3 | Medium | 2017-05-27 | 2017-05-22 | View |
Page 1620 of 17672, showing 5 records out of 88360 total, starting on record 8096, ending on 8100