Vendor CVEs
Open-Xchange
All CVEs
304 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29851 | Cri | 0.64 | 9.8 | 0.04 | Oct 25, 2022 | documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document. | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2022-23100 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | ||
| CVE-2020-12645 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. | ||
| CVE-2019-7158 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2019 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. | ||
| CVE-2017-13667 | Cri | 0.64 | 9.9 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF. | ||
| CVE-2017-5212 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control. | ||
| CVE-2017-5210 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure. | ||
| CVE-2017-17060 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2019 | OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions. | ||
| CVE-2017-5863 | Cri | 0.64 | 9.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2018-5752 | Hig | 0.61 | 8.8 | 0.05 | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations… | ||
| CVE-2026-42007 | Cri | 0.59 | 9.1 | 0.00 | Aug 28, 2026 | An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory… | ||
| CVE-2024-4367 | Hig | 0.59 | 8.8 | 0.71 | May 14, 2024 | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. | ||
| CVE-2023-29048 | Hig | 0.57 | 8.8 | 0.01 | Jan 8, 2024 | A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and… | ||
| CVE-2018-10986 | Hig | 0.57 | 8.8 | 0.00 | Jul 3, 2019 | OX Guard 2.8.0 has CSRF. | ||
| CVE-2017-8340 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2017-6912 | Hig | 0.57 | 8.8 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control. | ||
| CVE-2015-8542 | Hig | 0.57 | 8.8 | 0.02 | Dec 15, 2016 | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its… | ||
| CVE-2023-29051 | Hig | 0.53 | 8.1 | 0.01 | Jan 8, 2024 | User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects… | ||
| CVE-2019-14226 | Hig | 0.53 | 8.1 | 0.01 | Oct 14, 2019 | OX App Suite through 7.10.2 has Insecure Permissions. | ||
| CVE-2019-11521 | Hig | 0.53 | 8.1 | 0.02 | Aug 20, 2019 | OX App Suite 7.10.1 allows Content Spoofing. | ||
| CVE-2014-5238 | Hig | 0.51 | 7.8 | 0.02 | Jan 14, 2020 | XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document. | ||
| CVE-2023-29050 | Hig | 0.50 | 7.6 | 0.02 | Jan 8, 2024 | The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load… | ||
| CVE-2026-27852 | Hig | 0.49 | 7.5 | 0.00 | Aug 28, 2026 | An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can… | ||
| CVE-2025-30188 | Hig | 0.49 | 7.5 | 0.00 | Oct 31, 2025 | Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No… | ||
| CVE-2023-26454 | Hig | 0.49 | 7.6 | 0.00 | Nov 2, 2023 | Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL… | ||
| CVE-2023-26453 | Hig | 0.49 | 7.6 | 0.00 | Nov 2, 2023 | Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL… | ||
| CVE-2023-26452 | Hig | 0.49 | 7.6 | 0.00 | Nov 2, 2023 | Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by… | ||
| CVE-2023-26451 | Hig | 0.49 | 7.5 | 0.01 | Aug 2, 2023 | Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result,… | ||
| CVE-2023-26439 | Hig | 0.49 | 7.6 | 0.00 | Aug 2, 2023 | The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users… | ||
| CVE-2020-28944 | Hig | 0.49 | 7.5 | 0.02 | Apr 30, 2021 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. | ||
| CVE-2020-8543 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2020 | OX App Suite through 7.10.3 has Improper Input Validation. | ||
| CVE-2014-5236 | Hig | 0.49 | 7.5 | 0.04 | Jan 31, 2020 | Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument… | ||
| CVE-2019-7159 | Hig | 0.49 | 7.5 | 0.02 | Jun 18, 2019 | OX App Suite 7.10.1 and earlier allows Information Exposure. | ||
| CVE-2017-5211 | Hig | 0.49 | 7.5 | 0.01 | May 23, 2019 | Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing. | ||
| CVE-2017-12884 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2019 | OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure. | ||
| CVE-2016-4028 | Hig | 0.49 | 7.5 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with different error codes depending on whether the provided… | ||
| CVE-2026-40018 | Hig | 0.48 | 7.4 | 0.00 | Aug 28, 2026 | None None None No publicly available exploits are known. | ||
| CVE-2026-27851 | Hig | 0.48 | 7.4 | 0.01 | May 12, 2026 | When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on… | ||
| CVE-2025-30189 | Hig | 0.48 | 7.4 | 0.01 | Oct 31, 2025 | When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally… | ||
| CVE-2016-3174 | Hig | 0.48 | 7.4 | 0.01 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a… | ||
| CVE-2017-8777 | Hig | 0.47 | 7.2 | 0.01 | May 22, 2019 | Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization. | ||
| CVE-2023-41704 | Hig | 0.46 | 7.1 | 0.01 | Feb 12, 2024 | Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing… | ||
| CVE-2023-26440 | Hig | 0.46 | 7.1 | 0.00 | Aug 2, 2023 | The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have… | ||
| CVE-2023-26436 | Hig | 0.46 | 7.1 | 0.01 | Jun 20, 2023 | Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being… | ||
| CVE-2018-5753 | Med | 0.46 | 6.5 | 0.08 | Jun 16, 2018 | The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2)… | ||
| CVE-2018-5751 | Med | 0.46 | 6.5 | 0.09 | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the… | ||
| CVE-2017-17062 | Med | 0.46 | 6.5 | 0.04 | Jun 16, 2018 | The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management. | ||
| CVE-2026-33603 | Med | 0.44 | 6.8 | 0.00 | May 12, 2026 | Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications… | ||
| CVE-2026-24031 | Hig | 0.43 | 7.7 | 0.00 | Mar 27, 2026 | Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No… |
- risk 0.64cvss 9.8epss 0.04
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
- risk 0.64cvss 9.8epss 0.01
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- risk 0.64cvss 9.8epss 0.02
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
- risk 0.64cvss 9.9epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 is affected by: Incorrect Access Control.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Information Exposure.
- risk 0.64cvss 9.8epss 0.01
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
- risk 0.64cvss 9.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.61cvss 8.8epss 0.05
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations…
- risk 0.59cvss 9.1epss 0.00
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory…
- risk 0.59cvss 8.8epss 0.71
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- risk 0.57cvss 8.8epss 0.01
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and…
- risk 0.57cvss 8.8epss 0.00
OX Guard 2.8.0 has CSRF.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.
- risk 0.57cvss 8.8epss 0.02
An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the "id" and "cid" parameter to specify the current user by its…
- risk 0.53cvss 8.1epss 0.01
User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects…
- risk 0.53cvss 8.1epss 0.01
OX App Suite through 7.10.2 has Insecure Permissions.
- risk 0.53cvss 8.1epss 0.02
OX App Suite 7.10.1 allows Content Spoofing.
- risk 0.51cvss 7.8epss 0.02
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
- risk 0.50cvss 7.6epss 0.02
The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load…
- risk 0.49cvss 7.5epss 0.00
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can…
- risk 0.49cvss 7.5epss 0.00
Malicious or unintentional API requests can be used to add significant amount of data to caches. Caches may evict information that is required to operate the web frontend, which leads to unavailability of the component. Please deploy the provided updates and patch releases. No…
- risk 0.49cvss 7.6epss 0.00
Requests to fetch image metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL…
- risk 0.49cvss 7.6epss 0.00
Requests to cache an image could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by default. Arbitrary SQL…
- risk 0.49cvss 7.6epss 0.00
Requests to cache an image and return its metadata could be abused to include SQL queries that would be executed unchecked. Exploiting this vulnerability requires at least access to adjacent networks of the imageconverter service, which is not exposed to public networks by…
- risk 0.49cvss 7.5epss 0.01
Functions with insufficient randomness were used to generate authorization tokens of the integrated oAuth Authorization Service. Authorization codes were predictable for third parties and could be used to intercept and take over the client authorization process. As a result,…
- risk 0.49cvss 7.6epss 0.00
The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users…
- risk 0.49cvss 7.5epss 0.02
OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data.
- risk 0.49cvss 7.5epss 0.02
OX App Suite through 7.10.3 has Improper Input Validation.
- risk 0.49cvss 7.5epss 0.04
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument…
- risk 0.49cvss 7.5epss 0.02
OX App Suite 7.10.1 and earlier allows Information Exposure.
- risk 0.49cvss 7.5epss 0.01
Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.
- risk 0.49cvss 7.5epss 0.01
OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with different error codes depending on whether the provided…
- risk 0.48cvss 7.4epss 0.00
None None None No publicly available exploits are known.
- risk 0.48cvss 7.4epss 0.01
When safe filter is used with variable expansion, all following pipelines on the same string are incorrectly interpreted as safe too, enabling unsafe data to be unescaped. This can enable SQL / LDAP injection attacks when used in authentication. Avoid using safe filter until on…
- risk 0.48cvss 7.4epss 0.01
When cache is enabled, some passdb/userdb drivers incorrectly cache all users with same cache key, causing wrong cached information to be used for these users. After cached login, all subsequent logins are for same user. Install fixed version or disable caching either globally…
- risk 0.48cvss 7.4epss 0.01
An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a…
- risk 0.47cvss 7.2epss 0.01
Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.
- risk 0.46cvss 7.1epss 0.01
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing…
- risk 0.46cvss 7.1epss 0.00
The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have…
- risk 0.46cvss 7.1epss 0.01
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being…
- risk 0.46cvss 6.5epss 0.08
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2)…
- risk 0.46cvss 6.5epss 0.09
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the…
- risk 0.46cvss 6.5epss 0.04
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.
- risk 0.44cvss 6.8epss 0.00
Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the attacker is able to position itself between Dovecot and the client connection. If successful, the attacker can eavesdrop communications…
- risk 0.43cvss 7.7epss 0.00
Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows bypassing authentication for any user and user enumeration. Do not clear auth_username_chars. If this is not possible, install latest fixed version. No…
Page 1 of 7