Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Open Xchange Appsuite Office HIGH 7.8
CVE-2023-26440

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed w…

Fix: 8.11+
Fix from $1,950 2023-08-02
Open Xchange Appsuite Office MEDIUM 5.5
CVE-2023-26441

Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker wi…

Fix: 8.11+
Fix from $1,600 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26445

Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious …

Fix: after 7.10.6
Fix from $1,600 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26446

The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within th…

Fix: 8.12+
Fix from $1,600 2023-08-02
Open Xchange Appsuite Frontend MEDIUM 5.4
CVE-2023-26447

The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped…

Fix: after 7.10.6
Fix from $1,600 2023-08-02
Open Xchange Appsuite Backend HIGH 8.8
CVE-2023-26436

Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserializa…

Fix: 7.10.6+
Fix from $1,950 2023-06-20
Open Xchange Appsuite Backend MEDIUM 6.5
CVE-2023-26428

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other use…

Fix: 7.10.6 / 8.11.0+
Fix from $1,600 2023-06-20
Open Xchange Appsuite Backend MEDIUM 5.3
CVE-2023-26429

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and …

Fix: 7.10.6 / 8.11.0+
Fix from $1,600 2023-06-20
Open Xchange Appsuite Backend MEDIUM 5.0
CVE-2023-26435

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could disco…

Fix: 7.10.6+
Fix from $1,600 2023-06-20
Ox App Suite MEDIUM 6.5
CVE-2023-24603

OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an un…

Fix: 7.10.6+
Fix from $1,600 2023-05-29
Ox App Suite MEDIUM 6.1
CVE-2023-24601

OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.

Fix: 7.10.6+
Fix from $1,600 2023-05-29
Ox App Suite MEDIUM 6.1
CVE-2023-24602

OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.

Fix: 7.10.6+
Fix from $1,600 2023-05-29
Ox App Suite MEDIUM 5.3
CVE-2023-24597

OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

Fix: 7.10.6+
Fix from $1,600 2023-05-29
Ox App Suite MEDIUM 6.1
CVE-2022-37306

OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.

Fix: 7.10.6+
Fix from $1,600 2023-04-16
Ox App Suite MEDIUM 6.1
CVE-2022-43696

OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.

Fix: 7.10.6+
Fix from $1,600 2023-04-15
Ox App Suite MEDIUM 6.1
CVE-2022-43697

OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.

Fix: 7.10.6+
Fix from $1,600 2023-04-15
Open Xchange Appsuite MEDIUM 6.1
CVE-2022-37309

OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 6.1
CVE-2022-37310

OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 5.4
CVE-2022-29852

OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.

Fix: 7.10.5 / 8.2.324+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 5.4
CVE-2022-29853

OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 6.1
CVE-2022-37308

OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 6.1
CVE-2022-31469

OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 6.1
CVE-2022-37307

OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail sig…

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 5.3
CVE-2022-37311

OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 5.3
CVE-2022-37312

OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Open Xchange Appsuite MEDIUM 5.3
CVE-2022-37313

OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.

Fix: 7.10.5+
Fix from $1,600 2022-12-26
Ox App Suite MEDIUM 6.1
CVE-2022-31468

OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.

Fix: after 8.2
Fix from $1,600 2022-10-25
Ox App Suite CRITICAL 9.8
CVE-2022-29851

documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversio…

Fix: after 7.10.6
Fix from $2,300 2022-10-25
Ox App Suite CRITICAL 9.8
CVE-2022-23100

OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

Fix: after 7.10.6
Fix from $2,300 2022-07-27
Ox App Suite CRITICAL 9.8
CVE-2022-24405

OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

Fix: after 7.10.6
Fix from $2,300 2022-07-27