Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ox App Suite MEDIUM 5.3
CVE-2024-23193

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same ser…

Fix: 8.22+
Fix from $1,600 2024-05-06
Ox App Suite MEDIUM 6.1
CVE-2024-23186

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could p…

Fix: 8.22+
Fix from $1,600 2024-05-06
Ox App Suite MEDIUM 6.1
CVE-2024-23187

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers co…

Fix: 8.22+
Fix from $1,600 2024-05-06
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41706

Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availabilit…

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41707

Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please …

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 5.4
CVE-2023-41708

References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existi…

Fix: 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.5
CVE-2023-41705

Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please d…

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.1
CVE-2023-41703

User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with …

Fix: 7.10.6 / 8.20+
Fix from $1,600 2024-02-12
Open Xchange Appsuite MEDIUM 6.1
CVE-2023-41704

Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could…

Fix: 7.6.3 / 7.10.6+
Fix from $1,600 2024-02-12
Ox App Suite CRITICAL 9.6
CVE-2023-29050

The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i…

Fix: 7.10.6+
Fix from $2,300 2024-01-08
Ox App Suite HIGH 8.1
CVE-2023-29051

User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature …

Fix: 7.10.6+
Fix from $1,950 2024-01-08
Ox App Suite MEDIUM 6.1
CVE-2023-29049

The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account,…

Fix: 7.10.6+
Fix from $1,600 2024-01-08
Ox App Suite MEDIUM 5.4
CVE-2023-29052

Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could…

Mitigation only
Fix from $1,600 2024-01-08
Ox App Suite MEDIUM 5.4
CVE-2023-41710

User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could …

Fix: 7.10.6+
Fix from $1,600 2024-01-08
Ox App Suite HIGH 8.8
CVE-2023-29048

A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user…

Fix: 7.10.6+
Fix from $1,950 2024-01-08
Open Xchange Appsuite HIGH 7.3
CVE-2023-29047

Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL sta…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Open Xchange Appsuite MEDIUM 6.1
CVE-2023-29043

Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editi…

Fix: 7.10.6+
Fix from $1,600 2023-11-02
Open Xchange Appsuite MEDIUM 5.4
CVE-2023-29044

Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that wou…

Fix: 7.10.6+
Fix from $1,600 2023-11-02
Open Xchange Appsuite MEDIUM 5.4
CVE-2023-29045

Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected…

Fix: 7.10.6+
Fix from $1,600 2023-11-02
Open Xchange Appsuite HIGH 8.8
CVE-2023-26452

Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerabi…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Open Xchange Appsuite HIGH 8.8
CVE-2023-26453

Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least a…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Open Xchange Appsuite HIGH 8.8
CVE-2023-26454

Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at l…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Open Xchange Appsuite HIGH 7.8
CVE-2023-26455

RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th…

Fix: 7.10.6+
Fix from $1,950 2023-11-02
Ox Guard MEDIUM 5.4
CVE-2023-26456

Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user int…

Fix: 2.10.7+
Fix from $1,600 2023-11-02
Open Xchange Appsuite Backend HIGH 7.5
CVE-2023-26451

Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes …

Fix: after 8.11.0
Fix from $1,950 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26448

Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can …

Fix: after 7.10.6
Fix from $1,600 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26449

The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within …

Fix: after 7.10.6
Fix from $1,600 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26450

The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within…

Fix: after 7.10.6
Fix from $1,600 2023-08-02
Open Xchange Appsuite Backend CRITICAL 9.8
CVE-2023-26443

Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abus…

Fix: after 8.12
Fix from $2,300 2023-08-02
Open Xchange Appsuite Office HIGH 7.8
CVE-2023-26439

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement…

Fix: 8.11+
Fix from $1,950 2023-08-02