Vulnerability index

Browse CVEs

187 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Office MEDIUM 6.1
CVE-2015-7798

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

No fix yet
Fix from $1,600 2016-02-17
Office MEDIUM 6.1
CVE-2015-7797

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 6.1
CVE-2015-7796

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 6.1
CVE-2015-7795

Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via uns…

Mitigation only
Fix from $1,600 2016-02-17
Garoon HIGH 8.5
CVE-2015-5647

The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via…

Mitigation only
Fix from $1,950 2015-10-12
Garoon HIGH 8.5
CVE-2015-5646

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka Cy…

Patch available
Fix from $1,950 2015-10-12
Garoon HIGH 7.0
CVE-2015-5649

Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 mishandles authentication requests, which allows remote authenticated users to conduct LDAP inj…

Mitigation only
Fix from $1,950 2015-10-08
Remote Service Manager HIGH 7.8
CVE-2014-7266

Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2015-02-01
Office HIGH 9.0
CVE-2014-5314

Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to…

Fix: after 10.0.2
Fix from $1,950 2014-11-24
Garoon HIGH 10.0
CVE-2014-1987

The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.

Mitigation only
Fix from $1,950 2014-07-20
Garoon HIGH 7.5
CVE-2014-1996

Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial o…

Mitigation only
Fix from $1,950 2014-07-20
Garoon MEDIUM 6.0
CVE-2014-1989

Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspec…

Mitigation only
Fix from $1,600 2014-05-02
Remote Service Manager HIGH 7.8
CVE-2014-1983

Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (C…

Fix: after 3.1.0
Fix from $1,950 2014-04-19
Remote Service Manager MEDIUM 6.8
CVE-2014-1984

Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers t…

Fix: after 3.1.0
Fix from $1,600 2014-04-19
Garoon MEDIUM 6.5
CVE-2014-0821

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to e…

Mitigation only
Fix from $1,600 2014-02-27
Garoon MEDIUM 6.5
CVE-2013-6930

SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0…

Mitigation only
Fix from $1,600 2014-01-29
Garoon MEDIUM 6.5
CVE-2013-6931

SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via un…

Mitigation only
Fix from $1,600 2014-01-29
Garoon MEDIUM 6.5
CVE-2013-6929

SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API …

Fix: after 3.7
Fix from $1,600 2013-12-28
Garoon MEDIUM 5.8
CVE-2013-6006

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

Mitigation only
Fix from $1,600 2013-12-28
Garoon MEDIUM 6.8
CVE-2013-6004

Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 3.7
Fix from $1,600 2013-12-05
Garoon MEDIUM 6.5
CVE-2013-6001

SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands…

Fix: after 3.7
Fix from $1,600 2013-12-05
Garoon MEDIUM 5.0
CVE-2013-6002

The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

Fix: after 3.7
Fix from $1,600 2013-12-05
Cybozu Office MEDIUM 5.8
CVE-2013-3656

Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of …

Fix: after 9.1.0
Fix from $1,600 2013-07-20
Cybozu Live MEDIUM 6.8
CVE-2013-3646

The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or e…

Fix: after 2.0.0
Fix from $1,600 2013-06-18
Cybozu Live MEDIUM 6.8
CVE-2013-3647

The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive…

Fix: after 2.0.0
Fix from $1,600 2013-06-18
Cybozu Office MEDIUM 6.8
CVE-2013-2305

Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise be…

Fix: after 8.0.6
Fix from $1,600 2013-04-25
Cybozu Office MEDIUM 6.8
CVE-2013-3269

Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authenticati…

Fix: after 8
Fix from $1,600 2013-04-25
Garoon MEDIUM 6.0
CVE-2013-0701

SQL injection vulnerability in Cybozu Garoon 2.5.0 through 3.5.3 allows remote authenticated users to execute arbitrary SQL commands by leveraging a …

Mitigation only
Fix from $1,600 2013-02-14
Kunai HIGH 9.3
CVE-2012-4011

The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or …

Fix: after 2.0.5
Fix from $1,950 2012-09-08
Cybozu Live MEDIUM 6.8
CVE-2012-4008

The Cybozu Live application 1.0.4 and earlier for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information…

Fix: after 1.0.4
Fix from $1,600 2012-08-31