Skip to main content

Vendor archive

cybozu CVEs

Beta · best-effort

330 CVEs tagged to vendor cybozu8 Critical, 37 High, 269 Medium, 16 Low, 0 Unrated.

CVE-2014-0817

Published Feb 27, 2014

Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified v…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6931

Published Jan 29, 2014

SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6930

Published Jan 29, 2014

SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 throug…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6929

Published Dec 28, 2013

SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6006

Published Dec 28, 2013

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6005

Published Dec 13, 2013

Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6915

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or H…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6914

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspeci…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6913

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6912

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to in…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6910

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6909

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a report component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6908

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6907

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6906

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6902

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6901

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6900

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6004

Published Dec 5, 2013

Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6003

Published Dec 5, 2013

CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 276-300 of 330 CVEsPage 12 of 14