Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ox App Suite MEDIUM 6.5
CVE-2022-24406

OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Document…

Fix: after 7.10.6
Fix from $1,600 2022-07-27
Ox App Suite MEDIUM 6.1
CVE-2022-23101

OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.

Fix: after 7.10.6
Fix from $1,600 2022-07-27
App Suite MEDIUM 5.4
CVE-2022-23099

OX App Suite through 7.10.6 allows XSS by forcing block-wise read.

Fix: after 7.10.6
Fix from $1,600 2022-07-27
Ox App Suite MEDIUM 6.1
CVE-2021-44212

OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 6.1
CVE-2021-44213

OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 6.1
CVE-2021-44208

OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 6.1
CVE-2021-44209

OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 6.1
CVE-2021-44210

OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 5.4
CVE-2021-44211

OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.

Fix: after 7.10.5
Fix from $1,600 2022-03-28
Ox App Suite MEDIUM 6.5
CVE-2021-33491

OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail a…

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33492

OX App Suite 7.10.5 allows XSS via an OX Chat room name.

No fix yet
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33494

OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering.

No fix yet
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33495

OX App Suite 7.10.5 allows XSS via an OX Chat system message.

No fix yet
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-38375

OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-38377

OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID wit…

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.0
CVE-2021-33493

The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 5.4
CVE-2021-38374

OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 5.3
CVE-2021-38376

OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33488

chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33489

OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Ox App Suite MEDIUM 6.1
CVE-2021-33490

OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.

Fix: after 7.10.5
Fix from $1,600 2021-11-22
Open Xchange Documents MEDIUM 6.5
CVE-2021-28093

OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

Fix: 7.10.5+
Fix from $1,600 2021-07-30
Open Xchange Documents MEDIUM 6.5
CVE-2021-28094

OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.

Fix: 7.10.5+
Fix from $1,600 2021-07-30
Open Xchange Appsuite MEDIUM 6.1
CVE-2021-26698

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created…

No fix yet
Fix from $1,600 2021-07-22
Open Xchange Appsuite MEDIUM 6.1
CVE-2021-37402

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint …

Mitigation only
Fix from $1,600 2021-07-22
Open Xchange Appsuite MEDIUM 6.1
CVE-2021-37403

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created…

Mitigation only
Fix from $1,600 2021-07-22
Open Xchange Appsuite MEDIUM 5.4
CVE-2021-26699

OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter componen…

No fix yet
Fix from $1,600 2021-07-22
Open Xchange Appsuite MEDIUM 6.1
CVE-2020-28945

OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in …

Fix: after 7.10.4
Fix from $1,600 2021-05-03
Ox Guard HIGH 7.5
CVE-2020-28944

OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data.

Fix: after 2.10.4
Fix from $1,950 2021-04-30
Open Xchange Appsuite MEDIUM 6.5
CVE-2020-28943

OX App Suite 7.10.4 and earlier allows SSRF via a snippet.

Fix: after 7.10.4
Fix from $1,600 2021-04-30