Vulnerabilidades en Cybozu, Inc.

200 resultados
Análisis Vexday

Com 200 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, o perfil de exploração ativa da Cybozu, Inc. situa-se abaixo da média geral do catálogo, indicando baixa atratividade imediata para agentes de ameaça oportunistas. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere atenção contínua à validação de entrada e sanitização de saída nas aplicações do vendor. A CVE de maior risco identificada atualmente é CVE-2020-5537, com pontuação EPSS de 0,0293, refletindo probabilidade ainda baixa de exploração em larga escala no curto prazo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, embora o monitoramento contínuo permaneça recomendável dado o volume acumulado de registros.

CVE-2017-2092—Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HEPSS 0.9%CVE-2021-20775—Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the daEPSS 0.9%CVE-2021-20772—Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the titleEPSS 0.9%CVE-2022-44608HIGHUncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huEPSS 0.9%CVE-2018-0531—Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a foEPSS 0.9%CVE-2017-2114—Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script orEPSS 0.9%CVE-2018-0528—Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to accesEPSS 0.9%CVE-2018-0566—Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via EPSS 0.9%CVE-2022-33311—Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain tEPSS 0.9%CVE-2022-32283—Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the daEPSS 0.9%CVE-2022-29891—Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the EPSS 0.9%CVE-2022-25986—Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the EPSS 0.9%CVE-2018-0532—Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard databaEPSS 0.9%CVE-2017-2145—Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectoEPSS 0.9%CVE-2017-2144—Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.EPSS 0.8%CVE-2022-29471—Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin.EPSS 0.8%CVE-2022-31472—Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the dataEPSS 0.8%CVE-2022-30943—Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the dEPSS 0.8%CVE-2021-20806—Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conEPSS 0.8%CVE-2019-5947—Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or EPSS 0.8%