Vendor CVEs
Open-Xchange
All CVEs
304 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16716 | Med | 0.43 | 6.6 | 0.02 | Jan 6, 2020 | OX App Suite through 7.10.2 has Incorrect Access Control. | ||
| CVE-2016-6854 | Med | 0.43 | 6.1 | 0.03 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or… | ||
| CVE-2016-6853 | Med | 0.43 | 6.1 | 0.03 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting… | ||
| CVE-2016-6851 | Med | 0.43 | 6.1 | 0.03 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script… | ||
| CVE-2016-5740 | Med | 0.43 | 6.1 | 0.05 | Dec 15, 2016 | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the… | ||
| CVE-2026-73209 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2026 | An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly… | ||
| CVE-2026-52687 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2026 | An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating… | ||
| CVE-2026-40017 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2026 | An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not… | ||
| CVE-2026-40014 | Med | 0.42 | 6.5 | 0.00 | Aug 28, 2026 | An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for… | ||
| CVE-2026-27858 | Hig | 0.42 | 7.5 | 0.01 | Mar 27, 2026 | Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install… | ||
| CVE-2025-59032 | Hig | 0.42 | 7.5 | 0.01 | Mar 27, 2026 | ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively… | ||
| CVE-2024-23188 | Med | 0.42 | 6.5 | 0.01 | May 6, 2024 | Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information… | ||
| CVE-2024-23187 | Med | 0.42 | 6.5 | 0.00 | May 6, 2024 | Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user… | ||
| CVE-2024-23186 | Med | 0.42 | 6.5 | 0.01 | May 6, 2024 | E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch… | ||
| CVE-2023-41707 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related… | ||
| CVE-2023-41706 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing… | ||
| CVE-2023-41705 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is… | ||
| CVE-2023-26428 | Med | 0.42 | 6.5 | 0.01 | Jun 20, 2023 | Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not… | ||
| CVE-2023-24603 | Med | 0.42 | 6.5 | 0.01 | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data. | ||
| CVE-2022-24406 | Med | 0.42 | 6.5 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls. | ||
| CVE-2021-33491 | Med | 0.42 | 6.5 | 0.03 | Nov 22, 2021 | OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records. | ||
| CVE-2021-28094 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2021 | OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32. | ||
| CVE-2021-28093 | Med | 0.42 | 6.5 | 0.01 | Jul 30, 2021 | OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32. | ||
| CVE-2020-28943 | Med | 0.42 | 6.5 | 0.01 | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows SSRF via a snippet. | ||
| CVE-2021-23927 | Med | 0.42 | 6.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. | ||
| CVE-2020-8544 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows SSRF. | ||
| CVE-2020-8541 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows XXE attacks. | ||
| CVE-2018-12609 | Med | 0.42 | 6.5 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. | ||
| CVE-2018-9998 | Med | 0.42 | 6.5 | 0.02 | Jul 5, 2018 | Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action… | ||
| CVE-2026-27856 | Hig | 0.41 | 7.4 | 0.00 | Mar 27, 2026 | Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm… | ||
| CVE-2025-59025 | Med | 0.40 | 6.1 | 0.00 | Nov 27, 2025 | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known | ||
| CVE-2024-23192 | Med | 0.40 | 6.1 | 0.01 | Apr 8, 2024 | RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from… | ||
| CVE-2023-41703 | Med | 0.40 | 6.1 | 0.01 | Feb 12, 2024 | User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are… | ||
| CVE-2023-29043 | Med | 0.40 | 6.1 | 0.00 | Nov 2, 2023 | Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when… | ||
| CVE-2023-24602 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | ||
| CVE-2023-24601 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | ||
| CVE-2022-37306 | Med | 0.40 | 6.1 | 0.01 | Apr 16, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. | ||
| CVE-2022-43697 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. | ||
| CVE-2022-43696 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. | ||
| CVE-2022-37310 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI. | ||
| CVE-2022-37309 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. | ||
| CVE-2022-37308 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. | ||
| CVE-2022-37307 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature. | ||
| CVE-2022-31469 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI. | ||
| CVE-2022-31468 | Med | 0.40 | 6.1 | 0.01 | Oct 25, 2022 | OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter. | ||
| CVE-2022-23101 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. | ||
| CVE-2021-44213 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message. | ||
| CVE-2021-44212 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. | ||
| CVE-2021-44210 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data. | ||
| CVE-2021-44209 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. |
- risk 0.43cvss 6.6epss 0.02
OX App Suite through 7.10.2 has Incorrect Access Control.
- risk 0.43cvss 6.1epss 0.03
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or…
- risk 0.43cvss 6.1epss 0.03
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting…
- risk 0.43cvss 6.1epss 0.03
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script…
- risk 0.43cvss 6.1epss 0.05
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's location, will be presented to the user at the E-Mail App, depending on the…
- risk 0.42cvss 6.5epss 0.00
An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly…
- risk 0.42cvss 6.5epss 0.00
An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating…
- risk 0.42cvss 6.5epss 0.00
An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, which makes the IMAP THREAD command consume CPU disproportionate to the size of the message. This is a separate issue from CVE-2026-40014 and is not…
- risk 0.42cvss 6.5epss 0.00
An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the size of the message. When a mail client issues a THREAD command on the affected mailbox, this can cause degradation or denial of service for…
- risk 0.42cvss 7.5epss 0.01
Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install…
- risk 0.42cvss 7.5epss 0.01
ManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedly, making it unavailable for other users. Control access to ManageSieve port, or disable the service if it's not needed. Alternatively…
- risk 0.42cvss 6.5epss 0.01
Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information…
- risk 0.42cvss 6.5epss 0.00
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user…
- risk 0.42cvss 6.5epss 0.01
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch…
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related…
- risk 0.42cvss 6.5epss 0.01
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…
- risk 0.42cvss 6.5epss 0.01
Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not…
- risk 0.42cvss 6.5epss 0.01
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
- risk 0.42cvss 6.5epss 0.03
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
- risk 0.42cvss 6.5epss 0.01
OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, due to use of CRC32.
- risk 0.42cvss 6.5epss 0.01
OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
- risk 0.42cvss 6.4epss 0.01
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows XXE attacks.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
- risk 0.42cvss 6.5epss 0.02
Open-Xchange OX App Suite before 7.6.3-rev37, 7.8.x before 7.8.2-rev40, 7.8.3 before 7.8.3-rev48, and 7.8.4 before 7.8.4-rev28 include folder names in API error responses, which allows remote attackers to obtain sensitive information via the folder parameter in an "all" action…
- risk 0.41cvss 7.4epss 0.00
Doveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determine the configured credentials. Figuring out the credential will lead into full access to the affected component. Limit access to the doveadm…
- risk 0.40cvss 6.1epss 0.00
Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known
- risk 0.40cvss 6.1epss 0.01
RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or successfully luring users to compromised accounts. Attackers could perform malicious API requests or extract information from…
- risk 0.40cvss 6.1epss 0.01
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are…
- risk 0.40cvss 6.1epss 0.00
Presentations may contain references to images, which are user-controlled, and could include malicious script code that is being processed when editing a document. Script code embedded in malicious documents could be executed in the context of the user editing the document when…
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
Page 2 of 7