CVE-2013-6916
- EPSS 1.79%
- Veröffentlicht 05.12.2013 12:55:37
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6903
- EPSS 1.16%
- Veröffentlicht 05.12.2013 12:55:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6904
- EPSS 1.16%
- Veröffentlicht 05.12.2013 12:55:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6905
- EPSS 1.16%
- Veröffentlicht 05.12.2013 12:55:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6001
- EPSS 1.04%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
- EPSS 1.57%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
CVE-2013-6003
- EPSS 0.96%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors.
CVE-2013-6004
- EPSS 1.31%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.
CVE-2013-6900
- EPSS 1.16%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6901
- EPSS 1.16%
- Veröffentlicht 05.12.2013 12:55:30
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.