Vendor CVEs
Cybozu
All CVEs
331 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-20757 | Med | 0.28 | 4.3 | 0.01 | Aug 18, 2021 | Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege. | ||
| CVE-2021-20756 | Med | 0.28 | 4.3 | 0.01 | Aug 18, 2021 | Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege. | ||
| CVE-2021-20755 | Med | 0.28 | 4.3 | 0.01 | Aug 18, 2021 | Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege. | ||
| CVE-2021-20754 | Med | 0.28 | 4.3 | 0.01 | Aug 18, 2021 | Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege. | ||
| CVE-2021-20634 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors. | ||
| CVE-2021-20633 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors. | ||
| CVE-2021-20632 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors. | ||
| CVE-2021-20630 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors. | ||
| CVE-2021-20625 | Med | 0.28 | 4.3 | 0.01 | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors. | ||
| CVE-2020-5582 | Med | 0.28 | 4.3 | 0.01 | Jun 30, 2020 | Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors. | ||
| CVE-2020-5566 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2020 | Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'. | ||
| CVE-2020-5565 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2020 | Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'. | ||
| CVE-2019-6023 | Med | 0.28 | 4.3 | 0.01 | Dec 26, 2019 | Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'. | ||
| CVE-2019-5977 | Med | 0.28 | 4.3 | 0.01 | Sep 12, 2019 | Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'. | ||
| CVE-2019-5944 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'. | ||
| CVE-2019-5943 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'. | ||
| CVE-2019-5942 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'. | ||
| CVE-2019-5941 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the Report without access privileges via the application 'Multi Report'. | ||
| CVE-2019-5935 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information. | ||
| CVE-2019-5933 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'. | ||
| CVE-2019-5930 | Med | 0.28 | 4.3 | 0.01 | May 17, 2019 | Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'. | ||
| CVE-2018-0566 | Med | 0.28 | 4.3 | 0.01 | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors. | ||
| CVE-2018-0529 | Med | 0.28 | 4.3 | 0.01 | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors. | ||
| CVE-2018-0528 | Med | 0.28 | 4.3 | 0.01 | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors. | ||
| CVE-2018-0526 | Med | 0.28 | 4.3 | 0.01 | Jun 26, 2018 | Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors. | ||
| CVE-2018-0550 | Med | 0.28 | 4.3 | 0.01 | Apr 16, 2018 | Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors. | ||
| CVE-2018-0548 | Med | 0.28 | 4.3 | 0.01 | Apr 16, 2018 | Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors. | ||
| CVE-2018-0531 | Med | 0.28 | 4.3 | 0.01 | Apr 16, 2018 | Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors. | ||
| CVE-2017-10857 | Med | 0.28 | 4.3 | 0.01 | Oct 12, 2017 | Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function. | ||
| CVE-2017-2258 | Med | 0.28 | 4.3 | 0.02 | Aug 29, 2017 | Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications". | ||
| CVE-2016-7801 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors. | ||
| CVE-2016-4910 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors. | ||
| CVE-2016-4909 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2017 | Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors. | ||
| CVE-2016-4908 | Med | 0.28 | 4.3 | 0.01 | Jun 9, 2017 | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors. | ||
| CVE-2017-2116 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors. | ||
| CVE-2017-2115 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors. | ||
| CVE-2017-2095 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors. | ||
| CVE-2017-2094 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors. | ||
| CVE-2017-2093 | Med | 0.28 | 4.3 | 0.02 | Apr 28, 2017 | Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors. | ||
| CVE-2017-2091 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2017 | Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors. | ||
| CVE-2016-4841 | Med | 0.28 | 4.3 | 0.02 | Apr 21, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers. | ||
| CVE-2016-4844 | Med | 0.28 | 4.3 | 0.02 | Apr 20, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks. | ||
| CVE-2016-4842 | Med | 0.28 | 4.3 | 0.02 | Apr 20, 2017 | Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. | ||
| CVE-2016-1220 | Med | 0.28 | 4.3 | 0.01 | Apr 20, 2017 | Cybozu Garoon before 4.2.2 does not properly restrict access. | ||
| CVE-2016-4873 | Med | 0.28 | 4.3 | 0.01 | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function. | ||
| CVE-2016-4872 | Med | 0.28 | 4.3 | 0.02 | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail. | ||
| CVE-2016-4868 | Med | 0.28 | 4.3 | 0.02 | Apr 17, 2017 | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests. | ||
| CVE-2016-4867 | Med | 0.28 | 4.3 | 0.02 | Apr 17, 2017 | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. | ||
| CVE-2016-1196 | Med | 0.28 | 4.3 | 0.01 | Jun 19, 2016 | Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776. | ||
| CVE-2016-1192 | Med | 0.28 | 4.3 | 0.02 | Jun 19, 2016 | Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors. |
- risk 0.28cvss 4.3epss 0.01
Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
- risk 0.28cvss 4.3epss 0.01
Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.
- risk 0.28cvss 4.3epss 0.01
Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.
- risk 0.28cvss 4.3epss 0.01
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to bypass access restriction to alter the data for the file attached to Report via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Improper authorization vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to alter the application's data via the applications 'E-mail' and 'Messages'.
- risk 0.28cvss 4.3epss 0.01
Improper input validation vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows a remote authenticated attacker to alter the application's data via the applications 'Workflow' and 'MultiReport'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'.
- risk 0.28cvss 4.3epss 0.01
Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter mail header via the application 'E-Mail'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the contents of application 'Address' without modify privileges via the application 'Address'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to view the information without view privileges via the application 'Bulletin' and the application 'Cabinet'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to obtain files without access privileges via the Multiple Files Download function of application 'Cabinet'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction alter the Report without access privileges via the application 'Multi Report'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.1 allows remote authenticated attackers to bypass access restriction to change user information without access privileges via the Item function of User Information.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.10.0 allows remote authenticated attackers to bypass access restriction to view the Bulletin Board without view privileges via the application 'Bulletin'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.6.3 allows remote attackers to bypass access restriction to browse unauthorized pages via the application 'Management of Basic System'.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.6.1 allows authenticated attackers to bypass access restriction to perform arbitrary actions via "Cabinet" function.
- risk 0.28cvss 4.3epss 0.02
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.
- risk 0.28cvss 4.3epss 0.02
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.
- risk 0.28cvss 4.3epss 0.02
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
- risk 0.28cvss 4.3epss 0.02
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
- risk 0.28cvss 4.3epss 0.02
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon before 4.2.2 does not properly restrict access.
- risk 0.28cvss 4.3epss 0.01
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
- risk 0.28cvss 4.3epss 0.02
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
- risk 0.28cvss 4.3epss 0.02
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.
- risk 0.28cvss 4.3epss 0.02
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.
- risk 0.28cvss 4.3epss 0.01
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.
- risk 0.28cvss 4.3epss 0.02
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.
Page 5 of 7