VYPR

Vendor CVEs

Cybozu

All CVEs

331 total · sorted by risk
  • CVE-2015-7775MedJun 19, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.

  • CVE-2016-1152MedFeb 17, 2016
    risk 0.35cvss 5.4epss 0.01

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2015-8486.

  • CVE-2015-8486MedFeb 17, 2016
    risk 0.35cvss 5.4epss 0.01

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.

  • CVE-2015-8485MedFeb 17, 2016
    risk 0.35cvss 5.4epss 0.01

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.

  • CVE-2015-8484MedFeb 17, 2016
    risk 0.35cvss 5.4epss 0.01

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.

  • CVE-2024-31397MedJun 11, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.

  • CVE-2020-5588MedJun 30, 2020
    risk 0.32cvss 4.9epss 0.01

    Path traversal vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to obtain unintended information via unspecified vectors.

  • CVE-2020-5562MedApr 28, 2020
    risk 0.32cvss 4.9epss 0.01

    Server-side request forgery (SSRF) vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows a remote attacker with an administrative privilege to issue arbitrary HTTP requests to other web servers via V-CUBE Meeting function.

  • CVE-2019-5976MedSep 12, 2019
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via unspecified vectors.

  • CVE-2018-0533MedApr 16, 2018
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.

  • CVE-2017-2254MedAug 29, 2017
    risk 0.32cvss 4.9epss 0.01

    Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input

  • CVE-2022-29513MedJul 4, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote authenticated attacker with an administrative privilege to execute an arbitrary script.

  • CVE-2020-5586MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 4.10.3 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.

  • CVE-2020-5585MedJun 30, 2020
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.0.1 allows attacker with administrator rights to inject an arbitrary script via unspecified vectors.

  • CVE-2019-5932MedMay 17, 2019
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.6.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the application 'Portal'.

  • CVE-2017-2146MedJul 7, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.

  • CVE-2016-4866MedApr 17, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.

  • CVE-2016-4865MedApr 17, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.

  • CVE-2020-5573MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    Android App 'kintone mobile for Android' 1.0.0 to 2.5 allows an attacker to obtain credential information registered in the product via unspecified vectors.

  • CVE-2020-5572MedMay 29, 2020
    risk 0.30cvss 4.6epss 0.00

    Android App 'Mailwise for Android' 1.0.0 to 1.0.1 allows an attacker to obtain credential information registered in the product via unspecified vectors.

  • CVE-2024-31402MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.

  • CVE-2024-31398MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.

  • CVE-2024-31404MedJun 11, 2024
    risk 0.28cvss 4.3epss 0.00

    Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.

  • CVE-2023-27384MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.

  • CVE-2023-27304MedMay 23, 2023
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Message and Bulletin of Cybozu Garoon 4.6.0 to 5.9.2 allows a remote authenticated attacker to alter the data of Message and/or Bulletin.

  • CVE-2022-33311MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Address Book via unspecified vectors.

  • CVE-2022-32583MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Scheduler via unspecified vectors.

  • CVE-2022-32544MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to alter the data of Project via unspecified vectors.

  • CVE-2022-32283MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Cabinet via unspecified vectors.

  • CVE-2022-29891MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Custom App via unspecified vectors.

  • CVE-2022-25986MedAug 18, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the data of Scheduler.

  • CVE-2022-31472MedJul 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the data of Cabinet.

  • CVE-2022-30943MedJul 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the data of Bulletin.

  • CVE-2022-29471MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin.

  • CVE-2022-29467MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to obtain some data of Address.

  • CVE-2022-28718MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated attacker to alter the data of Bulletin.

  • CVE-2022-28692MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Scheduler.

  • CVE-2022-27807MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to disable to add Categories.

  • CVE-2022-27803MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Space.

  • CVE-2022-27661MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Workflow.

  • CVE-2022-26054MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Link.

  • CVE-2022-26051MedJul 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to alter the data of Portal.

  • CVE-2021-20775MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.

  • CVE-2021-20773MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.

  • CVE-2021-20772MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.

  • CVE-2021-20768MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.

  • CVE-2021-20763MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Operational restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the appropriate privilege.

  • CVE-2021-20762MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.

  • CVE-2021-20760MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.

  • CVE-2021-20759MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

Page 4 of 7