VYPR

Vendor CVEs

Open-Xchange

All CVEs

304 total · sorted by risk
  • CVE-2017-9809MedMay 22, 2019
    risk 0.35cvss 5.3epss 0.01

    OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.

  • CVE-2018-13104MedMar 21, 2019
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.8.4 and earlier allows XSS. Internal reference: 58742 (Bug ID)

  • CVE-2018-13103MedMar 21, 2019
    risk 0.35cvss 5.4epss 0.01

    OX App Suite 7.8.4 and earlier allows SSRF.

  • CVE-2018-12610MedJan 30, 2019
    risk 0.35cvss 5.3epss 0.01

    OX App Suite 7.8.4 and earlier allows Information Exposure.

  • CVE-2014-2078MedApr 10, 2018
    risk 0.35cvss 5.3epss 0.01

    The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.

  • CVE-2016-3173MedDec 15, 2016
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The aria-label parameter of tiles at the Portal can be used to inject script code. Those labels use the name of the file (e.g. an image) which gets displayed at the portal application. Using script code at…

  • CVE-2026-40016MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 times of the configured limit. Attacker can use this to degrade server performance and bypass configured CPU time limits for Sieve scripts.…

  • CVE-2024-23193MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.01

    E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared.…

  • CVE-2023-29047MedNov 2, 2023
    risk 0.34cvss 5.3epss 0.00

    Imageconverter API endpoints provided methods that were not sufficiently validating and sanitizing client input, allowing to inject arbitrary SQL statements. An attacker with access to the adjacent network and potentially API credentials, could read and modify database content…

  • CVE-2023-24597MedMay 29, 2023
    risk 0.34cvss 5.3epss 0.01

    OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

  • CVE-2023-26435MedJun 20, 2023
    risk 0.33cvss 5.0epss 0.01

    It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system…

  • CVE-2023-26431MedJun 20, 2023
    risk 0.33cvss 5.0epss 0.01

    IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight…

  • CVE-2020-15002MedOct 23, 2020
    risk 0.33cvss 5.0epss 0.02

    OX App Suite through 7.10.3 allows SSRF via the the /ajax/messaging/message message API.

  • CVE-2020-12644MedAug 31, 2020
    risk 0.33cvss 5.0epss 0.01

    OX App Suite 7.10.3 and earlier allows SSRF, related to the mail account API and the /folder/list API.

  • CVE-2020-9427MedJun 15, 2020
    risk 0.33cvss 5.0epss 0.01

    OX Guard 2.10.3 and earlier allows SSRF.

  • CVE-2019-18846MedFeb 21, 2020
    risk 0.33cvss 5.0epss 0.01

    OX App Suite through 7.10.2 allows SSRF.

  • CVE-2026-33606MedAug 28, 2026
    risk 0.31cvss 4.8epss 0.00

    Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with the stream protocol, for example during a migration. Injected commands can modify mailbox state on the destination during migration or…

  • CVE-2021-28095MedJul 30, 2021
    risk 0.31cvss 4.8epss 0.01

    OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.

  • CVE-2020-15004MedOct 23, 2020
    risk 0.31cvss 4.8epss 0.03

    OX App Suite through 7.10.3 allows stats/diagnostic?param= XSS.

  • CVE-2018-5756MedJun 16, 2018
    risk 0.31cvss 4.3epss 0.06

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via…

  • CVE-2026-42395MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure…

  • CVE-2026-42392MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned to the client. Process memory contents can be disclosed to the client, which may include sensitive data. Disable the…

  • CVE-2026-40015MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read and crash the process. The crash interrupts hibernated IMAP sessions handled by the affected process,…

  • CVE-2026-40013MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service compiles the script. This causes memory corruption and an observed crash of the ManageSieve process, resulting…

  • CVE-2026-33607MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor system for abnormal CPU usage and kill the offending process and lock account. Alternatively install fixed version. No publicly…

  • CVE-2026-33263MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode (default for community releases), only the new submission connection gets terminated. If…

  • CVE-2026-42006MedMay 12, 2026
    risk 0.28cvss 4.3epss 0.01

    An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left open. In particular, the fix was for closing braces, but you could still use open…

  • CVE-2023-29046MedNov 2, 2023
    risk 0.28cvss 4.3epss 0.00

    Connections to external data sources, like e-mail autoconfiguration, were not terminated in case they hit a timeout, instead those connections were logged. Some connections use user-controlled endpoints, which could be malicious and attempt to keep the connection open for an…

  • CVE-2023-26438MedAug 2, 2023
    risk 0.28cvss 4.3epss 0.01

    External service lookups for a number of protocols were vulnerable to a time-of-check/time-of-use (TOCTOU) weakness, involving the JDK DNS cache. Attackers that were timing DNS cache expiry correctly were able to inject configuration that would bypass existing network…

  • CVE-2023-26434MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-26433MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-26432MedJun 20, 2023
    risk 0.28cvss 4.3epss 0.01

    When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit…

  • CVE-2023-24604MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of header data.

  • CVE-2023-24600MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.

  • CVE-2023-24599MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."

  • CVE-2023-24598MedMay 29, 2023
    risk 0.28cvss 4.3epss 0.01

    OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.

  • CVE-2022-43699MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.00

    OX App Suite before 7.10.6-rev30 allows SSRF because e-mail account discovery disregards the deny-list and thus can be attacked by an adversary who controls the DNS records of an external domain (found in the host part of an e-mail address).

  • CVE-2022-43698MedApr 15, 2023
    risk 0.28cvss 4.3epss 0.00

    OX App Suite before 7.10.6-rev30 allows SSRF because changing a POP3 account disregards the deny-list.

  • CVE-2021-38378MedNov 22, 2021
    risk 0.28cvss 4.3epss 0.01

    OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.

  • CVE-2020-15003MedOct 23, 2020
    risk 0.28cvss 4.3epss 0.01

    OX App Suite through 7.10.3 allows Information Exposure because a user can obtain the IP address and User-Agent string of a different user (via the session API during shared Drive access).

  • CVE-2020-12643MedAug 31, 2020
    risk 0.28cvss 4.3epss 0.01

    OX App Suite 7.10.3 and earlier has Incorrect Access Control via an /api/subscriptions request for a snippet containing an email address.

  • CVE-2017-15029MedMay 23, 2019
    risk 0.28cvss 4.3epss 0.01

    Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected by: SSRF.

  • CVE-2016-6852MedDec 15, 2016
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on…

  • CVE-2016-4048MedDec 15, 2016
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can be abused to inject arbitrary text messages. Users may get tricked to follow…

  • CVE-2016-4047MedDec 15, 2016
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the generated document. As…

  • CVE-2026-27859MedMar 27, 2026
    risk 0.27cvss 5.3epss 0.00

    A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message causes mail delivery process to consume large amounts of CPU time. Use MTA capabilities to limit RFC 2231 MIME parameters in mail messages,…

  • CVE-2026-0394MedMar 27, 2026
    risk 0.27cvss 5.3epss 0.00

    When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowed characters, path traversal can happen if the domain component is directory partial. This allows inadvertently reading…

  • CVE-2025-59028MedMar 27, 2026
    risk 0.27cvss 5.3epss 0.00

    When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to fail. Invalid BASE64 data can be used to DoS a vulnerable server to break concurrent logins. Install fixed version or disable concurrency in…

  • CVE-2023-24605MedMay 29, 2023
    risk 0.27cvss 4.2epss 0.00

    OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading contact data, and renaming tokens.

  • CVE-2026-40203LowAug 28, 2026
    risk 0.24cvss 3.7epss 0.00

    When IMAP compression is enabled, the same compression state is reused across responses in a session, so response sizes depend on both attacker-supplied mail and other mail in the same mailbox. An attacker that can send mail to a user and can also observe the sizes of that…

Page 5 of 7