Vulnerabilities (CVE)

Filtered by vendor Cybozu Subscribe
Total 330 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1216 1 Cybozu 1 Garoon 2026-05-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.
CVE-2017-2172 1 Cybozu 1 Kunai 2026-05-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Cybozu KUNAI for Android 3.0.0 to 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-4844 1 Cybozu 1 Mailwise 2026-05-13 4.3 MEDIUM 4.3 MEDIUM
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
CVE-2016-4870 1 Cybozu 1 Office 2026-05-13 3.5 LOW 5.4 MEDIUM
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.
CVE-2017-2093 1 Cybozu 1 Garoon 2026-05-13 4.3 MEDIUM 4.3 MEDIUM
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.
CVE-2016-1213 1 Cybozu 1 Garoon 2026-05-13 5.8 MEDIUM 6.1 MEDIUM
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.
CVE-2016-1186 1 Cybozu 1 Kintone 2026-05-13 4.3 MEDIUM 5.9 MEDIUM
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
CVE-2016-4872 1 Cybozu 1 Office 2026-05-13 4.0 MEDIUM 4.3 MEDIUM
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
CVE-2016-1217 1 Cybozu 1 Garoon 2026-05-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.
CVE-2017-2094 1 Cybozu 1 Garoon 2026-05-13 4.0 MEDIUM 4.3 MEDIUM
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.
CVE-2016-1218 1 Cybozu 1 Garoon 2026-05-13 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
CVE-2017-2257 1 Cybozu 1 Garoon 2026-05-13 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via mail function.
CVE-2016-7833 1 Cybozu 1 Dezie 2026-05-13 6.4 MEDIUM 7.5 HIGH
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.
CVE-2016-1219 1 Cybozu 1 Garoon 2026-05-13 7.5 HIGH 9.8 CRITICAL
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.
CVE-2016-4866 1 Cybozu 1 Office 2026-05-13 3.5 LOW 4.8 MEDIUM
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.
CVE-2017-2116 1 Cybozu 1 Office 2026-05-13 4.0 MEDIUM 4.3 MEDIUM
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.
CVE-2016-7832 1 Cybozu 1 Dezie 2026-05-13 5.0 MEDIUM 5.3 MEDIUM
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to obtain an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.
CVE-2017-2144 1 Cybozu 1 Garoon 2026-05-13 5.8 MEDIUM 5.4 MEDIUM
Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.
CVE-2016-4873 1 Cybozu 1 Office 2026-05-13 4.0 MEDIUM 4.3 MEDIUM
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
CVE-2016-4868 1 Cybozu 1 Office 2026-05-13 4.3 MEDIUM 4.3 MEDIUM
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.