VYPR

Ox App Suite

by Open-Xchange

CVEs (86)

  • CVE-2022-29851CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2022-23100CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

  • CVE-2020-12645CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.01

    OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

  • CVE-2017-5212CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

  • CVE-2017-5210CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.

  • CVE-2017-5863CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2023-29048HigJan 8, 2024
    risk 0.57cvss 8.8epss 0.01

    A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and…

  • CVE-2017-8340HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2017-6912HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2023-29051HigJan 8, 2024
    risk 0.53cvss 8.1epss 0.01

    User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects…

  • CVE-2019-11521HigAug 20, 2019
    risk 0.53cvss 8.1epss 0.02

    OX App Suite 7.10.1 allows Content Spoofing.

  • CVE-2023-29050HigJan 8, 2024
    risk 0.50cvss 7.6epss 0.02

    The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load…

  • CVE-2020-8543HigJun 16, 2020
    risk 0.49cvss 7.5epss 0.02

    OX App Suite through 7.10.3 has Improper Input Validation.

  • CVE-2019-7159HigJun 18, 2019
    risk 0.49cvss 7.5epss 0.02

    OX App Suite 7.10.1 and earlier allows Information Exposure.

  • CVE-2017-5211HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

  • CVE-2024-23187MedMay 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user…

  • CVE-2024-23186MedMay 6, 2024
    risk 0.42cvss 6.5epss 0.01

    E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch…

  • CVE-2023-41707MedFeb 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related…

  • CVE-2023-24603MedMay 29, 2023
    risk 0.42cvss 6.5epss 0.01

    OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.

Page 1 of 5