VYPR
Vendor

Open-Xchange

Open-Xchange is an open source web-based office productivity software suite.

Founded 2005
Products
23
CVEs
286
Across products
396
Status
Private

Products

23

Recent CVEs

286
View all 286 CVEs →
  • CVE-2022-29851CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2022-23100CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

  • CVE-2020-12645CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.01

    OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

  • CVE-2019-7158CriJun 17, 2019
    risk 0.64cvss 9.8epss 0.02

    OX App Suite 7.10.0 and earlier has Incorrect Access Control.

  • CVE-2017-13667CriMay 23, 2019
    risk 0.64cvss 9.9epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

  • CVE-2017-5212CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.

  • CVE-2017-5210CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.

  • CVE-2017-17060CriMay 23, 2019
    risk 0.64cvss 9.8epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.

  • CVE-2017-5863CriMay 22, 2019
    risk 0.64cvss 9.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2018-5752HigJun 16, 2018
    risk 0.61cvss 8.8epss 0.08

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations…

  • CVE-2024-4367HigMay 14, 2024
    risk 0.59cvss 8.8epss 0.73

    A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

  • CVE-2023-29048HigJan 8, 2024
    risk 0.57cvss 8.8epss 0.01

    A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and…

  • CVE-2018-10986HigJul 3, 2019
    risk 0.57cvss 8.8epss 0.00

    OX Guard 2.8.0 has CSRF.

  • CVE-2017-8340HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2017-6912HigMay 22, 2019
    risk 0.57cvss 8.8epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

  • CVE-2015-8542HigDec 15, 2016
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its…

  • CVE-2023-29051HigJan 8, 2024
    risk 0.53cvss 8.1epss 0.01

    User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects…

  • CVE-2019-14226HigOct 14, 2019
    risk 0.53cvss 8.1epss 0.01

    OX App Suite through 7.10.2 has Insecure Permissions.

  • CVE-2019-11521HigAug 20, 2019
    risk 0.53cvss 8.1epss 0.02

    OX App Suite 7.10.1 allows Content Spoofing.