Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2024-23193
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same ser…
Ox App Suite
8.22+
MEDIUM 6.1
CVE-2024-23186
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could p…
Ox App Suite
8.22+
MEDIUM 6.1
CVE-2024-23187
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers co…
Ox App Suite
8.22+
MEDIUM 6.5
CVE-2023-41706
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availabilit…
Open Xchange Appsuite
7.6.3 / 7.10.6+
MEDIUM 6.5
CVE-2023-41707
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please …
Open Xchange Appsuite
7.6.3 / 7.10.6+
MEDIUM 5.4
CVE-2023-41708
References to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypass existi…
Open Xchange Appsuite
7.10.6+
MEDIUM 6.5
CVE-2023-41705
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please d…
Open Xchange Appsuite
7.6.3 / 7.10.6+
MEDIUM 6.1
CVE-2023-41703
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with …
Open Xchange Appsuite
7.10.6 / 8.20+
MEDIUM 6.1
CVE-2023-41704
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could…
Open Xchange Appsuite
7.6.3 / 7.10.6+
CRITICAL 9.6
CVE-2023-29050
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the i…
Ox App Suite
7.10.6+
HIGH 8.1
CVE-2023-29051
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature …
Ox App Suite
7.10.6+
MEDIUM 6.1
CVE-2023-29049
The "upsell" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account,…
Ox App Suite
7.10.6+
MEDIUM 5.4
CVE-2023-29052
Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could…
Ox App Suite
Mitigation only
MEDIUM 5.4
CVE-2023-41710
User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could …
Ox App Suite
7.10.6+
HIGH 8.8
CVE-2023-29048
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user…
Ox App Suite
7.10.6+
HIGH 7.3
CVE-2023-29047
Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL sta…
Open Xchange Appsuite
7.10.6+
MEDIUM 6.1
CVE-2023-29043
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editi…
Open Xchange Appsuite
7.10.6+
MEDIUM 5.4
CVE-2023-29044
Documents operations could be manipulated to contain invalid data types, possibly script code. Script code could be injected to an operation that wou…
Open Xchange Appsuite
7.10.6+
MEDIUM 5.4
CVE-2023-29045
Documents operations, in this case "drawing", could be manipulated to contain invalid data types, possibly script code. Script code could be injected…
Open Xchange Appsuite
7.10.6+
HIGH 8.8
CVE-2023-26452
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerabi…
Open Xchange Appsuite
7.10.6+
HIGH 8.8
CVE-2023-26453
Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least a…
Open Xchange Appsuite
7.10.6+
HIGH 8.8
CVE-2023-26454
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at l…
Open Xchange Appsuite
7.10.6+
HIGH 7.8
CVE-2023-26455
RMI was not requiring authentication when calling ChronosRMIService:setEventOrganizer. Attackers with local or adjacent network access could abuse th…
Open Xchange Appsuite
7.10.6+
MEDIUM 5.4
CVE-2023-26456
Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user int…
Ox Guard
2.10.7+
HIGH 7.5
CVE-2023-26451
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes …
Open Xchange Appsuite Backend
after 8.11.0
MEDIUM 5.4
CVE-2023-26448
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can …
Open Xchange Appsuite Frontend
after 7.10.6
MEDIUM 5.4
CVE-2023-26449
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within …
Open Xchange Appsuite Frontend
after 7.10.6
MEDIUM 5.4
CVE-2023-26450
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within…
Open Xchange Appsuite Frontend
after 7.10.6
CRITICAL 9.8
CVE-2023-26443
Full-text autocomplete search allows user-provided SQL syntax to be injected to SQL statements. With existing sanitization in place, this can be abus…
Open Xchange Appsuite Backend
after 8.12
HIGH 7.8
CVE-2023-26439
The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement…
Open Xchange Appsuite Office
8.11+