Vulnerability index

Browse CVEs

187 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Garoon MEDIUM 6.5
CVE-2016-1194

Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.

No fix yet
Fix from $1,600 2017-04-21
Garoon HIGH 8.8
CVE-2016-1218

SQL injection vulnerability in Cybozu Garoon before 4.2.2.

Fix: after 4.2.1
Fix from $1,950 2017-04-20
Mailwise MEDIUM 6.5
CVE-2016-4843

Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.

Mitigation only
Fix from $1,600 2017-04-20
Garoon MEDIUM 6.1
CVE-2016-1213

The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Garoon MEDIUM 6.1
CVE-2016-1214

Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Garoon MEDIUM 6.1
CVE-2016-1215

Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Garoon MEDIUM 6.1
CVE-2016-1216

Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Garoon MEDIUM 6.1
CVE-2016-1217

Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.

Fix: after 4.2.1
Fix from $1,600 2017-04-20
Garoon CRITICAL 9.8
CVE-2016-1219

Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

Fix: after 4.2.1
Fix from $2,300 2017-04-20
Office MEDIUM 6.5
CVE-2016-4869

Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.

Mitigation only
Fix from $1,600 2017-04-17
Office MEDIUM 6.5
CVE-2016-4871

Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.

No fix yet
Fix from $1,600 2017-04-17
Office MEDIUM 5.4
CVE-2016-4870

Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via …

Mitigation only
Fix from $1,600 2017-04-17
Garoon HIGH 7.5
CVE-2016-1193

Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.

No fix yet
Fix from $1,950 2016-06-25
Garoon MEDIUM 6.5
CVE-2016-1190

Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.

Mitigation only
Fix from $1,600 2016-06-25
Garoon HIGH 8.1
CVE-2016-1189

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet…

Mitigation only
Fix from $1,950 2016-06-25
Garoon MEDIUM 6.5
CVE-2016-1188

Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.

Mitigation only
Fix from $1,600 2016-06-25
Garoon MEDIUM 5.3
CVE-2016-1191

Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unsp…

Patch available
Fix from $1,600 2016-06-19
Garoon MEDIUM 6.1
CVE-2016-1197

Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspeci…

Patch available
Fix from $1,600 2016-06-19
Garoon HIGH 7.4
CVE-2016-1195

Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct ph…

Patch available
Fix from $1,950 2016-06-19
Garoon MEDIUM 5.4
CVE-2015-7775

Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecif…

Patch available
Fix from $1,600 2016-06-19
Office MEDIUM 6.5
CVE-2016-1153

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different v…

No fix yet
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2016-1152

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unsp…

Mitigation only
Fix from $1,600 2016-02-17
Office HIGH 8.8
CVE-2016-1151

Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication …

Mitigation only
Fix from $1,950 2016-02-17
Office MEDIUM 6.1
CVE-2016-1150

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 6.1
CVE-2016-1149

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 6.5
CVE-2015-8489

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a cra…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8486

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unsp…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8485

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8484

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a diff…

Mitigation only
Fix from $1,600 2016-02-17
Office HIGH 7.4
CVE-2015-8483

Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phish…

Mitigation only
Fix from $1,950 2016-02-17