Directory traversal vulnerability in Cybozu Collaborex, AG before 1.2(1.5), AG Pocket before 5.2(0.8), Mailwise before 3.0(0.3), and Garoon 1 before 1.5(4.1) allows remote authenticated users to read arbitrary files via unspecified vectors.
Conclusion & alert: CVE-2006-4491 is rated Moderate Risk (41.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.55%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.57% | 1.55% | -0.02% |
| 2 | 2025-09-24 | 1.51% | 1.57% | +0.06% |
| 3 | 2025-04-19 | — | 1.51% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cybozu | collaborex | — | cpe:2.3:a:cybozu:collaborex:*:*:*:*:*:*:*:* |
| cybozu | cybozu_ag | 1.2\(1.4\) | cpe:2.3:a:cybozu:cybozu_ag:1.2\(1.4\):*:*:*:*:*:*:* |
| cybozu | cybozu_pocket | 5.2\(0.7\) | cpe:2.3:a:cybozu:cybozu_pocket:5.2\(0.7\):*:*:*:*:*:*:* |
| cybozu | garoon_1 | 1.5\(4.0\) | cpe:2.3:a:cybozu:garoon_1:1.5\(4.0\):*:*:*:*:*:*:* |
| cybozu | mailwise | 3.0\(0.2\) | cpe:2.3:a:cybozu:mailwise:3.0\(0.2\):*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://cybozu.co.jp/products/dl/notice_060825/ | Patch |
| http://jvn.jp/jp/JVN%2390420168/index.html | Patch |
| http://secunia.com/advisories/21638 | Vendor Advisory |
| http://secunia.com/advisories/21656 | Patch Vendor Advisory |
| http://securitytracker.com/id?1016759 | Patch |
| http://www.osvdb.org/28262 |