Vulnerabilities > Cybozu > Garoon > 4.2.4

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-2255 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".
network
cybozu CWE-79
3.5
2017-08-29 CVE-2017-2254 Improper Input Validation vulnerability in Cybozu Garoon
Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input
network
low complexity
cybozu CWE-20
4.0
2017-07-07 CVE-2017-2146 Cross-site Scripting vulnerability in Cybozu Garoon
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.
network
cybozu CWE-79
3.5
2017-07-07 CVE-2017-2145 Session Fixation vulnerability in Cybozu Garoon
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
network
cybozu CWE-384
5.8