Cybozu develops a focused portfolio of widely deployed enterprise collaboration and communication platforms—particularly Garoon, Office, and Remote Service Manager—that are heavily represented in the vulnerability landscape despite the vendor's narrow product line. The vendor's disclosures concentrate on application-layer input-handling and information-exposure weaknesses, chiefly cross-site scripting, improper input validation, and sensitive information disclosure, reflecting the web-facing and data-handling demands of groupware and workplace-productivity software. These weakness classes are durable across the product family and recur as the primary exposure vector for this vendor; defenders tracking Cybozu should monitor its advisories for patches affecting web interfaces and data-access controls. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cybozu over time
Signals from CVEs in this vendor scope (330 CVEs).
330 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5537CRITICAL Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors. | May 25, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-5945CRITICAL Cybozu Garoon 4.2.4 to 4.10.1 allow remote attackers to obtain the users' credential information via the authentication of Cybozu Garoon. | May 17, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-0705CRITICAL Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests. | Jan 9, 2019 | 9.1 | 29 | NO | NO |
CVE-2014-5314HIGH Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-m | Nov 24, 2014 | 9.0 | 29 | NO | NO |
CVE-2016-7803HIGH SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function. | Jun 9, 2017 | 8.8 | 28 | NO | NO |
CVE-2016-1218HIGH SQL injection vulnerability in Cybozu Garoon before 4.2.2. | Apr 20, 2017 | 8.8 | 28 | NO | NO |
CVE-2018-16171HIGH Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors. | Jan 9, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-16169HIGH Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors. | Jan 9, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-0530HIGH SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Apr 16, 2018 | 8.8 | 27 | NO | NO |
CVE-2014-1983HIGH Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vec | Apr 19, 2014 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (330 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cybozu.
Media articles that mention a CVE ID that affects a product developed by Cybozu — matched by CVE ID, not by vendor name.