Garoon
by Cybozu
CVEs (201)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-1193 | Hig | 0.49 | 7.5 | 0.01 | Jun 25, 2016 | Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors. | ||
| CVE-2016-1195 | Hig | 0.48 | 7.4 | 0.02 | Jun 19, 2016 | Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | ||
| CVE-2019-5934 | Hig | 0.47 | 7.2 | 0.01 | May 17, 2019 | SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'. | ||
| CVE-2026-57279 | Med | 0.44 | 6.8 | 0.00 | Aug 10, 2026 | Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product. | ||
| CVE-2024-31399 | Med | 0.42 | 6.5 | 0.00 | Jun 11, 2024 | Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition. | ||
| CVE-2024-31400 | Med | 0.42 | 6.5 | 0.00 | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail. | ||
| CVE-2023-26595 | Med | 0.42 | 6.5 | 0.01 | May 23, 2023 | Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition. | ||
| CVE-2022-29512 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2022 | Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege. | ||
| CVE-2022-29892 | Med | 0.42 | 6.5 | 0.01 | Jul 4, 2022 | Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS). | ||
| CVE-2020-5643 | Med | 0.42 | 6.5 | 0.02 | Nov 6, 2020 | Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector. | ||
| CVE-2020-5587 | Med | 0.42 | 6.5 | 0.01 | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors. | ||
| CVE-2020-5583 | Med | 0.42 | 6.5 | 0.01 | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized Multi-Report's data via unspecified vectors. | ||
| CVE-2020-5581 | Med | 0.42 | 6.5 | 0.02 | Jun 30, 2020 | Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended information via unspecified vectors. | ||
| CVE-2016-7802 | Med | 0.42 | 6.5 | 0.02 | Jun 9, 2017 | Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | ||
| CVE-2016-1194 | Med | 0.42 | 6.5 | 0.02 | Apr 21, 2017 | Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service. | ||
| CVE-2016-1190 | Med | 0.42 | 6.5 | 0.01 | Jun 25, 2016 | Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors. | ||
| CVE-2016-1188 | Med | 0.42 | 6.5 | 0.01 | Jun 25, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors. | ||
| CVE-2026-20711 | Med | 0.40 | 6.1 | 0.00 | Feb 2, 2026 | Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords. | ||
| CVE-2022-27627 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2022 | Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser. | ||
| CVE-2021-20771 | Med | 0.40 | 6.1 | 0.01 | Aug 18, 2021 | Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors. |
- risk 0.49cvss 7.5epss 0.01
Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.
- risk 0.48cvss 7.4epss 0.02
Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.
- risk 0.44cvss 6.8epss 0.00
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.
- risk 0.42cvss 6.5epss 0.00
Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.
- risk 0.42cvss 6.5epss 0.00
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
- risk 0.42cvss 6.5epss 0.01
Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.
- risk 0.42cvss 6.5epss 0.01
Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS).
- risk 0.42cvss 6.5epss 0.02
Improper input validation vulnerability in Cybozu Garoon 5.0.0 to 5.0.2 allows a remote authenticated attacker to delete some data of the bulletin board via unspecified vector.
- risk 0.42cvss 6.5epss 0.01
Cybozu Garoon 4.0.0 to 5.0.1 allow remote authenticated attackers to obtain unintended information via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to obtain unauthorized Multi-Report's data via unspecified vectors.
- risk 0.42cvss 6.5epss 0.02
Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended information via unspecified vectors.
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
- risk 0.42cvss 6.5epss 0.02
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.
- risk 0.42cvss 6.5epss 0.01
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.
- risk 0.42cvss 6.5epss 0.01
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.
- risk 0.40cvss 6.1epss 0.00
Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attacker to execute an arbitrary script on the logged-in user's web browser.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
Page 2 of 11