VYPR

Vendor CVEs

Cybozu

All CVEs

331 total · sorted by risk
  • CVE-2020-5537CriMay 25, 2020
    risk 0.64cvss 9.8epss 0.03

    Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.

  • CVE-2019-5945CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon.

  • CVE-2016-1219CriApr 20, 2017
    risk 0.64cvss 9.8epss 0.03

    Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

  • CVE-2024-31401CriJun 11, 2024
    risk 0.59cvss 9.0epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.

  • CVE-2018-0705CriJan 9, 2019
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.

  • CVE-2021-20795HigOct 13, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to hijack the authentication of administrators and unintended operations may be performed via unspecified vectors.

  • CVE-2019-5931HigMay 17, 2019
    risk 0.57cvss 8.7epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.3 allows authenticated attackers to alter the information with privileges invoking the installer via unspecified vectors.

  • CVE-2018-16171HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.

  • CVE-2018-16169HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

  • CVE-2018-0607HigJul 26, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-0530HigApr 16, 2018
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2016-7803HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.

  • CVE-2016-4907HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.

  • CVE-2016-1218HigApr 20, 2017
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in Cybozu Garoon before 4.2.2.

  • CVE-2016-1151HigFeb 17, 2016
    risk 0.57cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.

  • CVE-2022-30602HigJul 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to alter the file information and/or delete the files.

  • CVE-2022-29484HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space.

  • CVE-2020-5580HigJun 30, 2020
    risk 0.53cvss 8.1epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to view and/or alter Single sign-on settings via unspecified vectors.

  • CVE-2018-16170HigJan 9, 2019
    risk 0.53cvss 8.1epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-0673HigNov 15, 2018
    risk 0.53cvss 8.1epss 0.01

    Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2016-1189HigJun 25, 2016
    risk 0.53cvss 8.1epss 0.01

    Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors.

  • CVE-2021-20758HigAug 18, 2021
    risk 0.52cvss 8.0epss 0.00

    Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.

  • CVE-2026-22888HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to unauthorized alteration of portal settings, potentially blocking access to the product.

  • CVE-2024-23304HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

  • CVE-2022-44608HigDec 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huge storage space, which may result in a denial-of-service (DoS) condition.

  • CVE-2020-5584HigJun 30, 2020
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allow remote attackers to obtain unintended information via unspecified vectors.

  • CVE-2020-5567HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Application Menu.

  • CVE-2019-5991HigSep 12, 2019
    risk 0.49cvss 7.6epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-16178HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function.

  • CVE-2018-0704HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.

  • CVE-2018-0703HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.

  • CVE-2018-0702HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.

  • CVE-2016-7833HigJun 9, 2017
    risk 0.49cvss 7.5epss 0.02

    Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.

  • CVE-2016-1193HigJun 25, 2016
    risk 0.49cvss 7.5epss 0.02

    Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.

  • CVE-2016-1195HigJun 19, 2016
    risk 0.48cvss 7.4epss 0.02

    Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

  • CVE-2015-8483HigFeb 17, 2016
    risk 0.48cvss 7.4epss 0.01

    Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

  • CVE-2019-5934HigMay 17, 2019
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.0 allows attacker with administrator rights to execute arbitrary SQL commands via the Log Search function of application 'logging'.

  • CVE-2026-57279MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

  • CVE-2016-1187MedApr 21, 2017
    risk 0.44cvss 6.8epss 0.01

    Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.

  • CVE-2024-39817MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.

  • CVE-2024-31399MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.

  • CVE-2024-31400MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.

  • CVE-2023-46278MedNov 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Uncontrolled resource consumption vulnerability in Cybozu Remote Service 4.1.0 to 4.1.1 allows a remote authenticated attacker to consume huge storage space or cause significantly delayed communication.

  • CVE-2022-26838MedAug 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.

  • CVE-2023-26595MedMay 23, 2023
    risk 0.42cvss 6.5epss 0.01

    Denial-of-service (DoS) vulnerability in Message of Cybozu Garoon 4.10.0 to 5.9.2 allows a remote authenticated attacker to cause a denial of service condition.

  • CVE-2022-32453MedAug 18, 2022
    risk 0.42cvss 6.5epss 0.01

    HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter the data of the product via unspecified vectors.

  • CVE-2022-29512MedJul 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Exposure of sensitive information to an unauthorized actor issue in multiple applications of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data without the viewing privilege.

  • CVE-2022-29892MedJul 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to repeatedly display errors in certain functions and cause a denial-of-service (DoS).

  • CVE-2021-20804MedOct 13, 2021
    risk 0.42cvss 6.5epss 0.01

    Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition via unspecified vectors.

  • CVE-2021-20801MedOct 13, 2021
    risk 0.42cvss 6.5epss 0.01

    Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors. This issue occurs only when using Mozilla Firefox.

Page 1 of 7