Cybozu

Garoon

198 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.06%
  • Veröffentlicht 02.05.2014 10:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

  • EPSS 1.06%
  • Veröffentlicht 02.05.2014 10:55:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspecified API calls.

  • EPSS 0.96%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 does not properly manage sessions, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors.

  • EPSS 1.49%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • EPSS 1.04%
  • Veröffentlicht 27.02.2014 01:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

SQL injection vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6930 a...

  • EPSS 1.04%
  • Veröffentlicht 29.01.2014 05:37:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x before 3.7.3 allows remote authenticated users to ex...

  • EPSS 1.04%
  • Veröffentlicht 29.01.2014 05:37:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.

  • EPSS 1.99%
  • Veröffentlicht 28.12.2013 04:53:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

  • EPSS 1.55%
  • Veröffentlicht 28.12.2013 04:53:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.

  • EPSS 1.16%
  • Veröffentlicht 05.12.2013 12:55:37
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.