Vulnerabilidades em Cybozu, Inc.

200 resultados
Análise Vexday

Com 200 CVEs catalogadas e nenhuma presença no catálogo KEV da CISA, o perfil de exploração ativa da Cybozu, Inc. situa-se abaixo da média geral do catálogo, indicando baixa atratividade imediata para agentes de ameaça oportunistas. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), o que sugere atenção contínua à validação de entrada e sanitização de saída nas aplicações do vendor. A CVE de maior risco identificada atualmente é CVE-2020-5537, com pontuação EPSS de 0,0293, refletindo probabilidade ainda baixa de exploração em larga escala no curto prazo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, embora o monitoramento contínuo permaneça recomendável dado o volume acumulado de registros.

CVE-2017-2092Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HEPSS 0.9%CVE-2021-20775Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the daEPSS 0.9%CVE-2021-20772Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the titleEPSS 0.9%CVE-2022-44608HIGHUncontrolled resource consumption vulnerability in Cybozu Remote Service 4.0.0 to 4.0.3 allows a remote authenticated attacker to consume huEPSS 0.9%CVE-2018-0531Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a foEPSS 0.9%CVE-2017-2114Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script orEPSS 0.9%CVE-2018-0528Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to accesEPSS 0.9%CVE-2018-0566Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via EPSS 0.9%CVE-2022-33311Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain tEPSS 0.9%CVE-2022-32283Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the daEPSS 0.9%CVE-2022-29891Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the EPSS 0.9%CVE-2022-25986Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attacker to obtain the EPSS 0.9%CVE-2018-0532Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard databaEPSS 0.9%CVE-2017-2145Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectoEPSS 0.9%CVE-2017-2144Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.EPSS 0.8%CVE-2022-29471Browse restriction bypass vulnerability in Bulletin of Cybozu Garoon allows a remote authenticated attacker to obtain the data of Bulletin.EPSS 0.8%CVE-2022-31472Browse restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker to obtain the dataEPSS 0.8%CVE-2022-30943Browsing restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.9.1 allows a remote authenticated attacker to obtain the dEPSS 0.8%CVE-2021-20806Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conEPSS 0.8%CVE-2019-5947Cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.1 allows remote authenticated attackers to inject arbitrary web script or EPSS 0.8%