CVE-2018-0673
- EPSS 0.58%
- Veröffentlicht 15.11.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:42
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
CVE-2018-0607
- EPSS 0.64%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:34
SQL injection vulnerability in the Notifications application in the Cybozu Garoon 3.5.0 to 4.6.2 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2018-0530
- EPSS 0.61%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2018-0531
- EPSS 0.17%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.
- EPSS 0.18%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.
CVE-2018-0533
- EPSS 0.75%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:25
Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.
- EPSS 0.14%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:27
Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.
CVE-2018-0549
- EPSS 0.17%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:27
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2018-0550
- EPSS 0.14%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:27
Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.
CVE-2018-0551
- EPSS 0.17%
- Veröffentlicht 16.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:27
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.