VYPR

Vendor CVEs

Cybozu

All CVEs

331 total · sorted by risk
  • CVE-2021-20757MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.

  • CVE-2021-20756MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.

  • CVE-2021-20755MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.

  • CVE-2021-20754MedAug 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.

  • CVE-2021-20634MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.

  • CVE-2021-20633MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.

  • CVE-2021-20632MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors.

  • CVE-2021-20630MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.

  • CVE-2021-20625MedMar 18, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors.

  • CVE-2020-5582MedJun 30, 2020
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors.

  • CVE-2020-5566MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'.

  • CVE-2020-5565MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.

  • CVE-2019-6023MedDec 26, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'.

  • CVE-2019-5977MedSep 12, 2019
    risk 0.28cvss 4.3epss 0.01

    Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.

  • CVE-2019-5944MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.

  • CVE-2019-5943MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'.

  • CVE-2019-5942MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.

  • CVE-2019-5941MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the Report without access privileges via the application 'Multi Report'.

  • CVE-2019-5935MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.

  • CVE-2019-5933MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.

  • CVE-2019-5930MedMay 17, 2019
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'.

  • CVE-2018-0566MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors.

  • CVE-2018-0529MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.

  • CVE-2018-0528MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.

  • CVE-2018-0526MedJun 26, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors.

  • CVE-2018-0550MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.

  • CVE-2018-0548MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.

  • CVE-2018-0531MedApr 16, 2018
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.

  • CVE-2017-10857MedOct 12, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.

  • CVE-2017-2258MedAug 29, 2017
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".

  • CVE-2016-7801MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.

  • CVE-2016-4910MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.

  • CVE-2016-4909MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.

  • CVE-2016-4908MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.

  • CVE-2017-2116MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.

  • CVE-2017-2115MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.

  • CVE-2017-2095MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.

  • CVE-2017-2094MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

  • CVE-2017-2093MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.

  • CVE-2017-2091MedApr 28, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.

  • CVE-2016-4841MedApr 21, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.

  • CVE-2016-4844MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.

  • CVE-2016-4842MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.

  • CVE-2016-1220MedApr 20, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon before 4.2.2 does not properly restrict access.

  • CVE-2016-4873MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.01

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.

  • CVE-2016-4872MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.

  • CVE-2016-4868MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.02

    Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

  • CVE-2016-4867MedApr 17, 2017
    risk 0.28cvss 4.3epss 0.02

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.

  • CVE-2016-1196MedJun 19, 2016
    risk 0.28cvss 4.3epss 0.01

    Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.

  • CVE-2016-1192MedJun 19, 2016
    risk 0.28cvss 4.3epss 0.02

    Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.

Page 5 of 7