VYPR

Garoon

by Cybozu

CVEs (201)

  • CVE-2017-2144MedJul 7, 2017
    risk 0.35cvss 5.4epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.

  • CVE-2017-2092MedApr 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1191MedJun 19, 2016
    risk 0.35cvss 5.3epss 0.02

    Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.

  • CVE-2015-7775MedJun 19, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.

  • CVE-2024-31397MedJun 11, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.

  • CVE-2020-5588MedJun 30, 2020
    risk 0.32cvss 4.9epss 0.01

    Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors.

  • CVE-2020-5562MedApr 28, 2020
    risk 0.32cvss 4.9epss 0.01

    Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function.

  • CVE-2019-5976MedSep 12, 2019
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.

  • CVE-2018-0533MedApr 16, 2018
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.

  • CVE-2017-2254MedAug 29, 2017
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input

  • CVE-2022-29513MedJul 4, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary script.

  • CVE-2020-5586MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.

  • CVE-2020-5585MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.

  • CVE-2019-5932MedMay 17, 2019
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Portal'.

  • CVE-2017-2146MedJul 7, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.

  • CVE-2024-31402MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.

  • CVE-2024-31398MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.

  • CVE-2024-31404MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.

  • CVE-2023-27384MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.

  • CVE-2023-27304MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Message and Bulletin of Cybozu Garoon 4.6.0 to 5.9.2 allows a remote authenticated attacker to alter the data of Message and/or Bulletin.

Page 5 of 11