Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2022-24406 OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Document… Ox App Suite after 7.10.6 Fix from $1,6002022-07-27 MEDIUM 6.1 CVE-2022-23101 OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. Ox App Suite after 7.10.6 Fix from $1,6002022-07-27 MEDIUM 5.4 CVE-2022-23099 OX App Suite through 7.10.6 allows XSS by forcing block-wise read. App Suite after 7.10.6 Fix from $1,6002022-07-27 MEDIUM 6.1 CVE-2021-44212 OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 6.1 CVE-2021-44213 OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 6.1 CVE-2021-44208 OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 6.1 CVE-2021-44209 OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 6.1 CVE-2021-44210 OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 5.4 CVE-2021-44211 OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature. Ox App Suite after 7.10.5 Fix from $1,6002022-03-28 MEDIUM 6.5 CVE-2021-33491 OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail a… Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33492 OX App Suite 7.10.5 allows XSS via an OX Chat room name. Ox App Suite No fix yet Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33494 OX App Suite 7.10.5 allows XSS via an OX Chat room title during typing rendering. Ox App Suite No fix yet Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33495 OX App Suite 7.10.5 allows XSS via an OX Chat system message. Ox App Suite No fix yet Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-38375 OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-38377 OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID wit… Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.0 CVE-2021-33493 The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 5.4 CVE-2021-38374 OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app loader URL. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 5.3 CVE-2021-38376 OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of the login API call. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33488 chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33489 OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.1 CVE-2021-33490 OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. Ox App Suite after 7.10.5 Fix from $1,6002021-11-22 MEDIUM 6.5 CVE-2021-28093 OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32. Open Xchange Documents 7.10.5+ Fix from $1,6002021-07-30 MEDIUM 6.5 CVE-2021-28094 OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32. Open Xchange Documents 7.10.5+ Fix from $1,6002021-07-30 MEDIUM 6.1 CVE-2021-26698 OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created… Open Xchange Appsuite No fix yet Fix from $1,6002021-07-22 MEDIUM 6.1 CVE-2021-37402 OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint … Open Xchange Appsuite Mitigation only Fix from $1,6002021-07-22 MEDIUM 6.1 CVE-2021-37403 OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created… Open Xchange Appsuite Mitigation only Fix from $1,6002021-07-22 MEDIUM 5.4 CVE-2021-26699 OX App Suite before 7.10.3-rev4 and 7.10.4 before 7.10.4-rev4 allows SSRF via a shared SVG document that is mishandled by the imageconverter componen… Open Xchange Appsuite No fix yet Fix from $1,6002021-07-22 MEDIUM 6.1 CVE-2020-28945 OX App Suite 7.10.4 and earlier allows XSS via crafted content to reach an undocumented feature, such as ![](http://onerror=Function.constructor, in … Open Xchange Appsuite after 7.10.4 Fix from $1,6002021-05-03 HIGH 7.5 CVE-2020-28944 OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. Ox Guard after 2.10.4 Fix from $1,9502021-04-30 MEDIUM 6.5 CVE-2020-28943 OX App Suite 7.10.4 and earlier allows SSRF via a snippet. Open Xchange Appsuite after 7.10.4 Fix from $1,6002021-04-30