| CVE-2013-6930 |
medium |
— |
6.5 |
|
|
cybozu |
13y ago |
SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x b… |
| CVE-2013-6929 |
medium |
— |
6.5 |
|
|
cybozu |
13y ago |
SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input. |
| CVE-2013-6006 |
medium |
— |
5.8 |
|
|
cybozu |
13y ago |
Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request. |
| CVE-2013-6005 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button. |
| CVE-2013-6916 |
medium |
— |
4.3 |
|
|
cybozumicrosoftgoogle |
13y ago |
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitr… |
| CVE-2013-6915 |
low |
— |
3.5 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified … |
| CVE-2013-6914 |
low |
— |
3.5 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6913 |
low |
— |
3.5 |
|
|
cybozumicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML … |
| CVE-2013-6912 |
low |
— |
3.5 |
|
|
cybozumicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to inject arbitrary web s… |
| CVE-2013-6911 |
low |
— |
3.5 |
|
|
cybozumozillamicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in the bulletin-board component in Cybozu Garoon before 3.7.2, when Internet Explorer or Firefox is used, allows remote authenticated users to inject arbitrar… |
| CVE-2013-6910 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6909 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a report component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6908 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6907 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6906 |
medium |
— |
4.3 |
|
|
cybozumicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML … |
| CVE-2013-6905 |
medium |
— |
4.3 |
|
|
cybozumozillamicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML … |
| CVE-2013-6904 |
medium |
— |
4.3 |
|
|
cybozumicrosoftmozilla |
13y ago |
Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML v… |
| CVE-2013-6903 |
medium |
— |
4.3 |
|
|
cybozumozillamicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HT… |
| CVE-2013-6902 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6901 |
medium |
— |
4.3 |
|
|
cybozumozilla |
13y ago |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vect… |
| CVE-2013-6900 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6004 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors. |
| CVE-2013-6003 |
low |
— |
3.5 |
|
|
cybozu |
13y ago |
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vect… |
| CVE-2013-6002 |
medium |
— |
5.0 |
|
|
cybozu |
13y ago |
The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors. |
| CVE-2013-6001 |
medium |
— |
6.5 |
|
|
cybozu |
13y ago |
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2013-4703 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the top-page customization feature in Cybozu Office before 9.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-4698 |
low |
— |
3.5 |
|
|
cybozu |
13y ago |
Cybozu Mailwise 5.0.4 and 5.0.5 allows remote authenticated users to obtain sensitive e-mail content intended for different persons in opportunistic circumstances by reading Subject header lines with… |
| CVE-2013-3656 |
medium |
— |
5.8 |
|
|
cybozu |
13y ago |
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL. |
| CVE-2013-3647 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that place… |
| CVE-2013-3646 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.… |
| CVE-2013-3269 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mob… |
| CVE-2013-2305 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the a… |
| CVE-2013-0702 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 3.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-0701 |
medium |
— |
6.0 |
|
|
cybozu |
14y ago |
SQL injection vulnerability in Cybozu Garoon 2.5.0 through 3.5.3 allows remote authenticated users to execute arbitrary SQL commands by leveraging a logging privilege. |
| CVE-2012-4013 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a cra… |
| CVE-2012-4012 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application th… |
| CVE-2012-4009 |
medium |
— |
6.8 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted applicatio… |
| CVE-2012-4008 |
medium |
— |
6.8 |
|
|
cybozu |
14y ago |
The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web … |
| CVE-2011-2677 |
medium |
— |
5.5 |
|
|
cybozu |
15y ago |
Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to mani… |
| CVE-2011-1335 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user lis… |
| CVE-2011-1334 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote att… |
| CVE-2011-1333 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading gr… |
| CVE-2011-1332 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CV… |
| CVE-2010-2029 |
medium |
— |
5.8 |
|
|
cybozu |
16y ago |
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the uni… |