Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-23193 E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same ser… Ox App Suite 8.22+ Fix from $1,6002024-05-06 MEDIUM 6.1 CVE-2024-23186 E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could p… Ox App Suite 8.22+ Fix from $1,6002024-05-06 MEDIUM 6.1 CVE-2024-23187 Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers co… Ox App Suite 8.22+ Fix from $1,6002024-05-06 MEDIUM 6.5 CVE-2023-41706 Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availabilit… Open Xchange Appsuite 7.6.3 / 7.10.6+ Fix from $1,6002024-02-12 MEDIUM 6.5 CVE-2023-41707 Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please … Open Xchange Appsuite 7.6.3 / 7.10.6+ Fix from $1,6002024-02-12 MEDIUM 5.4 CVE-2023-41708 References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existi… Open Xchange Appsuite 7.10.6+ Fix from $1,6002024-02-12 MEDIUM 6.5 CVE-2023-41705 Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please d… Open Xchange Appsuite 7.6.3 / 7.10.6+ Fix from $1,6002024-02-12 MEDIUM 6.1 CVE-2023-41703 User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with … Open Xchange Appsuite 7.10.6 / 8.20+ Fix from $1,6002024-02-12 MEDIUM 6.1 CVE-2023-41704 Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could… Open Xchange Appsuite 7.6.3 / 7.10.6+ Fix from $1,6002024-02-12 CRITICAL 9.6 CVE-2023-29050 The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i… Ox App Suite 7.10.6+ Fix from $2,3002024-01-08 HIGH 8.1 CVE-2023-29051 User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature … Ox App Suite 7.10.6+ Fix from $1,9502024-01-08 MEDIUM 6.1 CVE-2023-29049 The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account,… Ox App Suite 7.10.6+ Fix from $1,6002024-01-08 MEDIUM 5.4 CVE-2023-29052 Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could… Ox App Suite Mitigation only Fix from $1,6002024-01-08 MEDIUM 5.4 CVE-2023-41710 User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could … Ox App Suite 7.10.6+ Fix from $1,6002024-01-08 HIGH 8.8 CVE-2023-29048 A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user… Ox App Suite 7.10.6+ Fix from $1,9502024-01-08 HIGH 7.3 CVE-2023-29047 Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL sta… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 MEDIUM 6.1 CVE-2023-29043 Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editi… Open Xchange Appsuite 7.10.6+ Fix from $1,6002023-11-02 MEDIUM 5.4 CVE-2023-29044 Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that wou… Open Xchange Appsuite 7.10.6+ Fix from $1,6002023-11-02 MEDIUM 5.4 CVE-2023-29045 Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected… Open Xchange Appsuite 7.10.6+ Fix from $1,6002023-11-02 HIGH 8.8 CVE-2023-26452 Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerabi… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 HIGH 8.8 CVE-2023-26453 Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least a… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 HIGH 8.8 CVE-2023-26454 Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at l… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 HIGH 7.8 CVE-2023-26455 RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th… Open Xchange Appsuite 7.10.6+ Fix from $1,9502023-11-02 MEDIUM 5.4 CVE-2023-26456 Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user int… Ox Guard 2.10.7+ Fix from $1,6002023-11-02 HIGH 7.5 CVE-2023-26451 Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes … Open Xchange Appsuite Backend after 8.11.0 Fix from $1,9502023-08-02 MEDIUM 5.4 CVE-2023-26448 Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can … Open Xchange Appsuite Frontend after 7.10.6 Fix from $1,6002023-08-02 MEDIUM 5.4 CVE-2023-26449 The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within … Open Xchange Appsuite Frontend after 7.10.6 Fix from $1,6002023-08-02 MEDIUM 5.4 CVE-2023-26450 The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within… Open Xchange Appsuite Frontend after 7.10.6 Fix from $1,6002023-08-02 CRITICAL 9.8 CVE-2023-26443 Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abus… Open Xchange Appsuite Backend after 8.12 Fix from $2,3002023-08-02 HIGH 7.8 CVE-2023-26439 The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement… Open Xchange Appsuite Office 8.11+ Fix from $1,9502023-08-02