Filtered by vendor Cybozu Subscriptions
Total 324 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-20768 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.
CVE-2021-20760 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.
CVE-2021-20764 1 Cybozu 1 Garoon 2024-08-03 5.3 Medium
Improper input validation vulnerability in Attaching Files of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to alter the data of Attaching Files.
CVE-2021-20761 1 Cybozu 1 Garoon 2024-08-03 2.7 Low
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker with an administrative privilege to alter the data of E-mail without the appropriate privilege.
CVE-2021-20766 1 Cybozu 1 Garoon 2024-08-03 6.1 Medium
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20758 1 Cybozu 1 Garoon 2024-08-03 8.0 High
Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authentication of administrators and perform an arbitrary operation via unspecified vectors.
CVE-2021-20774 1 Cybozu 1 Garoon 2024-08-03 5.4 Medium
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20762 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.
CVE-2021-20770 1 Cybozu 1 Garoon 2024-08-03 5.4 Medium
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20755 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Portal without the viewing privilege.
CVE-2021-20756 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to obtain the data of Address without the viewing privilege.
CVE-2021-20754 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.
CVE-2021-20759 1 Cybozu 1 Garoon 2024-08-03 4.3 Medium
Operational restrictions bypass vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Portal without the appropriate privilege.
CVE-2021-20753 1 Cybozu 1 Garoon 2024-08-03 5.4 Medium
Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20627 1 Cybozu 1 Office 2024-08-03 6.1 Medium
Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20626 1 Cybozu 1 Office 2024-08-03 6.5 Medium
Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via unspecified vectors.
CVE-2021-20632 1 Cybozu 1 Office 2024-08-03 4.3 Medium
Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors.
CVE-2021-20633 1 Cybozu 1 Office 2024-08-03 4.3 Medium
Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.
CVE-2021-20634 1 Cybozu 1 Office 2024-08-03 4.3 Medium
Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.
CVE-2021-20629 1 Cybozu 1 Office 2024-08-03 6.1 Medium
Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.