Open-Xchange
Open-Xchange is an open source web-based office productivity software suite.
Products
23- 213 CVEs
- 86 CVEs
- 17 CVEs
- 17 CVEs
- 14 CVEs
- 12 CVEs
- 9 CVEs
- 8 CVEs
- 4 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
- 0 CVEs
Recent CVEs
286| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29851 | Cri | 0.64 | 9.8 | 0.04 | Oct 25, 2022 | documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document. | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2022-23100 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | ||
| CVE-2020-12645 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. | ||
| CVE-2019-7158 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2019 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. | ||
| CVE-2017-13667 | Cri | 0.64 | 9.9 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. | ||
| CVE-2017-5212 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control. | ||
| CVE-2017-5210 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure. | ||
| CVE-2017-17060 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions. | ||
| CVE-2017-5863 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2018-5752 | Hig | 0.61 | 8.8 | 0.08 | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations… | ||
| CVE-2024-4367 | Hig | 0.59 | 8.8 | 0.73 | May 14, 2024 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | ||
| CVE-2023-29048 | Hig | 0.57 | 8.8 | 0.01 | Jan 8, 2024 | A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and… | ||
| CVE-2018-10986 | Hig | 0.57 | 8.8 | 0.00 | Jul 3, 2019 | OX Guard 2.8.0 has CSRF. | ||
| CVE-2017-8340 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2017-6912 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2015-8542 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2016 | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its… | ||
| CVE-2023-29051 | Hig | 0.53 | 8.1 | 0.01 | Jan 8, 2024 | User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects… | ||
| CVE-2019-14226 | Hig | 0.53 | 8.1 | 0.01 | Oct 14, 2019 | OX App Suite through 7.10.2 has Insecure Permissions. | ||
| CVE-2019-11521 | Hig | 0.53 | 8.1 | 0.02 | Aug 20, 2019 | OX App Suite 7.10.1 allows Content Spoofing. |
- risk 0.64cvss 9.8epss 0.04
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
- risk 0.64cvss 9.8epss 0.01
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- risk 0.64cvss 9.8epss 0.02
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
- risk 0.64cvss 9.9epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
- risk 0.64cvss 9.8epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.61cvss 8.8epss 0.08
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations…
- risk 0.59cvss 8.8epss 0.73
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- risk 0.57cvss 8.8epss 0.01
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and…
- risk 0.57cvss 8.8epss 0.00
OX Guard 2.8.0 has CSRF.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its…
- risk 0.53cvss 8.1epss 0.01
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects…
- risk 0.53cvss 8.1epss 0.01
OX App Suite through 7.10.2 has Insecure Permissions.
- risk 0.53cvss 8.1epss 0.02
OX App Suite 7.10.1 allows Content Spoofing.