| CVE-2013-6908 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6907 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6906 |
medium |
— |
4.3 |
|
|
cybozumicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML … |
| CVE-2013-6905 |
medium |
— |
4.3 |
|
|
cybozumozillamicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML … |
| CVE-2013-6904 |
medium |
— |
4.3 |
|
|
cybozumicrosoftmozilla |
13y ago |
Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML v… |
| CVE-2013-6903 |
medium |
— |
4.3 |
|
|
cybozumozillamicrosoft |
13y ago |
Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HT… |
| CVE-2013-6902 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6901 |
medium |
— |
4.3 |
|
|
cybozumozilla |
13y ago |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vect… |
| CVE-2013-6900 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-6004 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors. |
| CVE-2013-6002 |
medium |
— |
5.0 |
|
|
cybozu |
13y ago |
The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors. |
| CVE-2013-6001 |
medium |
— |
6.5 |
|
|
cybozu |
13y ago |
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
| CVE-2013-4703 |
medium |
— |
4.3 |
|
|
cybozu |
13y ago |
Cross-site scripting (XSS) vulnerability in the top-page customization feature in Cybozu Office before 9.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-3656 |
medium |
— |
5.8 |
|
|
cybozu |
13y ago |
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL. |
| CVE-2013-3647 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application that place… |
| CVE-2013-3646 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.… |
| CVE-2013-3269 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mob… |
| CVE-2013-2305 |
medium |
— |
6.8 |
|
|
cybozu |
13y ago |
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the a… |
| CVE-2013-0702 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 3.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2013-0701 |
medium |
— |
6.0 |
|
|
cybozu |
14y ago |
SQL injection vulnerability in Cybozu Garoon 2.5.0 through 3.5.3 allows remote authenticated users to execute arbitrary SQL commands by leveraging a logging privilege. |
| CVE-2012-4013 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu KUNAI Browser for Remote Service application beta for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a cra… |
| CVE-2012-4012 |
medium |
— |
4.3 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted application th… |
| CVE-2012-4009 |
medium |
— |
6.8 |
|
|
cybozu |
14y ago |
The WebView class in the Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary JavaScript code, and obtain sensitive information, via a crafted applicatio… |
| CVE-2012-4008 |
medium |
— |
6.8 |
|
|
cybozu |
14y ago |
The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web … |
| CVE-2011-2677 |
medium |
— |
5.5 |
|
|
cybozu |
15y ago |
Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and attendance) via unspecified vectors related to mani… |
| CVE-2011-1335 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user lis… |
| CVE-2011-1334 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote att… |
| CVE-2011-1333 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Office 6 and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading gr… |
| CVE-2011-1332 |
medium |
— |
4.3 |
|
|
cybozu |
15y ago |
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CV… |
| CVE-2010-2029 |
medium |
— |
5.8 |
|
|
cybozu |
16y ago |
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the uni… |