OX App Suite
by OX App Suite
CVEs (66)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29851 | Cri | 0.64 | 9.8 | 0.04 | Oct 25, 2022 | documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document. | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2019-7158 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2019 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. | ||
| CVE-2019-14226 | Hig | 0.53 | 8.1 | 0.01 | Oct 14, 2019 | OX App Suite through 7.10.2 has Insecure Permissions. | ||
| CVE-2020-8543 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2020 | OX App Suite through 7.10.3 has Improper Input Validation. | ||
| CVE-2023-41706 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing… | ||
| CVE-2023-41705 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is… | ||
| CVE-2023-24603 | Med | 0.42 | 6.5 | 0.01 | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data. | ||
| CVE-2022-24406 | Med | 0.42 | 6.5 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls. | ||
| CVE-2021-33491 | Med | 0.42 | 6.5 | 0.02 | Nov 22, 2021 | OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records. | ||
| CVE-2020-8544 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows SSRF. | ||
| CVE-2018-12609 | Med | 0.42 | 6.5 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. | ||
| CVE-2023-24602 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | ||
| CVE-2023-24601 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | ||
| CVE-2022-43697 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. | ||
| CVE-2022-43696 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. | ||
| CVE-2022-37309 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. | ||
| CVE-2022-37308 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. | ||
| CVE-2022-37307 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature. | ||
| CVE-2022-31469 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI. |
- risk 0.64cvss 9.8epss 0.04
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.02
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
- risk 0.53cvss 8.1epss 0.01
OX App Suite through 7.10.2 has Insecure Permissions.
- risk 0.49cvss 7.5epss 0.02
OX App Suite through 7.10.3 has Improper Input Validation.
- risk 0.42cvss 6.5epss 0.01
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…
- risk 0.42cvss 6.5epss 0.01
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
- risk 0.42cvss 6.5epss 0.02
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Page 1 of 4