Show filters
328 Total Results
Displaying 1-10 of 328
Sort by:
Attacker Value
Unknown

CVE-2024-39817

Disclosure Date: August 06, 2024 (last updated September 12, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user who can login to the product to view data that the user does not have access by conducting 'search' under certain conditions in Custom App.
Attacker Value
Unknown

CVE-2024-39457

Disclosure Date: July 19, 2024 (last updated August 23, 2024)
Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user’s web browser.
Attacker Value
Unknown

CVE-2024-31402

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete the data of Shared To-Dos.
Attacker Value
Unknown

CVE-2024-31399

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, processing a crafted mail may cause a denial-of-service (DoS) condition.
Attacker Value
Unknown

CVE-2024-31398

Disclosure Date: June 11, 2024 (last updated August 23, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product may obtain information on the list of users.
Attacker Value
Unknown

CVE-2024-31397

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user who can log in to the product with the administrative privilege may be able to cause a denial-of-service (DoS) condition.
0
Attacker Value
Unknown

CVE-2024-31404

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.
0
Attacker Value
Unknown

CVE-2024-31403

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.
0
Attacker Value
Unknown

CVE-2024-31401

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the web browser of the user who is logging in to the product.
0
Attacker Value
Unknown

CVE-2024-31400

Disclosure Date: June 11, 2024 (last updated June 11, 2024)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
0