Skip to main content

Vendor/product archive

cybozu / garoon CVEs

Beta · best-effort

198 CVEs tagged to cybozu / garoon4 Critical, 23 High, 159 Medium, 12 Low, 0 Unrated.

CVE-2016-4906

Published Jun 9, 2017

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2095

Published Apr 28, 2017

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unsp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2094

Published Apr 28, 2017

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2093

Published Apr 28, 2017

Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2092

Published Apr 28, 2017

Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2091

Published Apr 28, 2017

Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1194

Published Apr 21, 2017

Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1217

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1216

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1215

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1214

Published Apr 20, 2017

Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1213

Published Apr 20, 2017

The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1219

Published Apr 20, 2017

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1193

Published Jun 25, 2016

Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1190

Published Jun 25, 2016

Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1189

Published Jun 25, 2016

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1188

Published Jun 25, 2016

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1196

Published Jun 19, 2016

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a di…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1192

Published Jun 19, 2016

Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1191

Published Jun 19, 2016

Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7776

Published Jun 19, 2016

Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail mess…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1197

Published Jun 19, 2016

Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vuln…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1195

Published Jun 19, 2016

Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted U…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 198 CVEsPage 6 of 8