Skip to main content

Vendor archive

cybozu CVEs

Beta · best-effort

330 CVEs tagged to vendor cybozu8 Critical, 37 High, 269 Medium, 16 Low, 0 Unrated.

CVE-2015-8486

Published Feb 17, 2016

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8485

Published Feb 17, 2016

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8484

Published Feb 17, 2016

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8483

Published Feb 17, 2016

Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7798

Published Feb 17, 2016

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7797

Published Feb 17, 2016

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7796

Published Feb 17, 2016

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7795

Published Feb 17, 2016

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5647

Published Oct 12, 2015

The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVD…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5646

Published Oct 12, 2015

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVDB-863 and CyVDB-867.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5649

Published Oct 8, 2015

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP injection attacks, and consequent…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7266

Published Feb 1, 2015

Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) vi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1996

Published Jul 20, 2014

Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial of service, via an API call.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1995

Published Jul 20, 2014

Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web scri…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1994

Published Jul 20, 2014

Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTM…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1993

Published Jul 20, 2014

The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1992

Published Jul 20, 2014

Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3.7 SP4 allows remote authenticated users to inject arbitrar…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1987

Published Jul 20, 2014

The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1989

Published May 2, 2014

Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspecified API calls.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1988

Published May 2, 2014

The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-1984

Published Apr 19, 2014

Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unsp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1983

Published Apr 19, 2014

Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown ve…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0821

Published Feb 27, 2014

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0820

Published Feb 27, 2014

Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 330 CVEsPage 11 of 14