Show filters
197 Total Results
Displaying 1-10 of 197
Sort by:
Attacker Value
Unknown

CVE-2024-39457

Disclosure Date: July 19, 2024 (last updated August 23, 2024)
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.
Attacker Value
Unknown

CVE-2024-31402

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
Attacker Value
Unknown

CVE-2024-31399

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.
Attacker Value
Unknown

CVE-2024-31398

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
Attacker Value
Unknown

CVE-2024-31397

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.
0
Attacker Value
Unknown

CVE-2024-31404

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.
0
Attacker Value
Unknown

CVE-2024-31403

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.
0
Attacker Value
Unknown

CVE-2024-31401

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.
0
Attacker Value
Unknown

CVE-2024-31400

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
0
Attacker Value
Unknown

CVE-2023-27384

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Operation restriction bypass vulnerability in MultiReport of Cybozu Garoon 5.15.0 allows a remote authenticated attacker to alter the data of MultiReport.