Cybozu

Garoon

198 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Veröffentlicht 02.05.2014 10:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

  • EPSS 0.22%
  • Veröffentlicht 02.05.2014 10:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspecified API calls.

  • EPSS 0.22%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors.

  • EPSS 0.21%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • EPSS 0.39%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 a...

  • EPSS 0.39%
  • Veröffentlicht 29.01.2014 05:37:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x before 3.7.3 allows remote authenticated users to ex...

  • EPSS 0.39%
  • Veröffentlicht 29.01.2014 05:37:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.

  • EPSS 0.12%
  • Veröffentlicht 28.12.2013 04:53:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

  • EPSS 0.44%
  • Veröffentlicht 28.12.2013 04:53:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.

  • EPSS 0.33%
  • Veröffentlicht 05.12.2013 12:55:37
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.