Vendor CVEs
OX App Suite
All CVEs
79 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29851 | Cri | 0.64 | 9.8 | 0.04 | Oct 25, 2022 | documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document. | ||
| CVE-2022-24405 | Cri | 0.64 | 9.8 | 0.03 | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. | ||
| CVE-2020-12645 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2020 | OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption. | ||
| CVE-2019-7158 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2019 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. | ||
| CVE-2019-14226 | Hig | 0.53 | 8.1 | 0.01 | Oct 14, 2019 | OX App Suite through 7.10.2 has Insecure Permissions. | ||
| CVE-2020-8543 | Hig | 0.49 | 7.5 | 0.02 | Jun 16, 2020 | OX App Suite through 7.10.3 has Improper Input Validation. | ||
| CVE-2023-41706 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing… | ||
| CVE-2023-41705 | Med | 0.42 | 6.5 | 0.01 | Feb 12, 2024 | Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is… | ||
| CVE-2023-24603 | Med | 0.42 | 6.5 | 0.01 | May 29, 2023 | OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data. | ||
| CVE-2022-24406 | Med | 0.42 | 6.5 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls. | ||
| CVE-2021-33491 | Med | 0.42 | 6.5 | 0.03 | Nov 22, 2021 | OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records. | ||
| CVE-2020-28943 | Med | 0.42 | 6.5 | 0.01 | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows SSRF via a snippet. | ||
| CVE-2021-23927 | Med | 0.42 | 6.4 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request. | ||
| CVE-2020-8544 | Med | 0.42 | 6.5 | 0.01 | Jun 16, 2020 | OX App Suite through 7.10.3 allows SSRF. | ||
| CVE-2018-12609 | Med | 0.42 | 6.5 | 0.01 | Jan 30, 2019 | OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery. | ||
| CVE-2023-24602 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title. | ||
| CVE-2023-24601 | Med | 0.40 | 6.1 | 0.00 | May 29, 2023 | OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree. | ||
| CVE-2022-37306 | Med | 0.40 | 6.1 | 0.01 | Apr 16, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger. | ||
| CVE-2022-43697 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob. | ||
| CVE-2022-43696 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2023 | OX App Suite before 7.10.6-rev20 allows XSS via upsell ads. | ||
| CVE-2022-37310 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI. | ||
| CVE-2022-37309 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name. | ||
| CVE-2022-37308 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages. | ||
| CVE-2022-37307 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature. | ||
| CVE-2022-31469 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2022 | OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI. | ||
| CVE-2022-31468 | Med | 0.40 | 6.1 | 0.01 | Oct 25, 2022 | OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter. | ||
| CVE-2022-23101 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. | ||
| CVE-2021-44212 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring. | ||
| CVE-2021-44209 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO. | ||
| CVE-2021-44208 | Med | 0.40 | 6.1 | 0.01 | Mar 28, 2022 | OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat. | ||
| CVE-2021-38377 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results. | ||
| CVE-2021-38375 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message. | ||
| CVE-2021-33495 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite 7.10.5 allows XSS via an OX Chat system message. | ||
| CVE-2021-33490 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature. | ||
| CVE-2021-33489 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file. | ||
| CVE-2021-33488 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2021 | chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook. | ||
| CVE-2021-37403 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used. | ||
| CVE-2021-37402 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2021 | OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled. | ||
| CVE-2021-31934 | Med | 0.40 | 6.1 | 0.01 | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone. | ||
| CVE-2021-23936 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the subject of a task. | ||
| CVE-2021-23935 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code. | ||
| CVE-2021-23934 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code. | ||
| CVE-2021-23933 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL. | ||
| CVE-2021-23932 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename. | ||
| CVE-2021-23931 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via an inline binary file. | ||
| CVE-2021-23930 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile. | ||
| CVE-2021-23929 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI. | ||
| CVE-2021-23928 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2021 | OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string. | ||
| CVE-2020-24701 | Med | 0.40 | 6.1 | 0.07 | Jan 12, 2021 | OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI). | ||
| CVE-2019-16717 | Med | 0.40 | 6.1 | 0.02 | Jan 6, 2020 | OX App Suite through 7.10.2 has XSS. |
- risk 0.64cvss 9.8epss 0.04
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.
- risk 0.64cvss 9.8epss 0.03
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- risk 0.64cvss 9.8epss 0.01
OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.
- risk 0.64cvss 9.8epss 0.02
OX App Suite 7.10.0 and earlier has Incorrect Access Control.
- risk 0.53cvss 8.1epss 0.01
OX App Suite through 7.10.2 has Insecure Permissions.
- risk 0.49cvss 7.5epss 0.02
OX App Suite through 7.10.3 has Improper Input Validation.
- risk 0.42cvss 6.5epss 0.01
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing…
- risk 0.42cvss 6.5epss 0.01
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is…
- risk 0.42cvss 6.5epss 0.01
OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to injection into internal Documentconverter API calls.
- risk 0.42cvss 6.5epss 0.03
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.10.4 and earlier allows SSRF via a snippet.
- risk 0.42cvss 6.4epss 0.01
OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
- risk 0.42cvss 6.5epss 0.01
OX App Suite through 7.10.3 allows SSRF.
- risk 0.42cvss 6.5epss 0.01
OX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.6-rev30 allows XSS via an upsell trigger.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev30 allows XSS via an activity tracking adapter defined by jslob.
- risk 0.40cvss 6.1epss 0.00
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.5 allows XSS via an OX Chat system message.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via a crafted snippet in a shared mail signature.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.5 allows XSS via JavaScript code in a shared XCF file.
- risk 0.40cvss 6.1epss 0.01
chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.
- risk 0.40cvss 6.1epss 0.01
OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.
- risk 0.40cvss 6.1epss 0.01
OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that is mishandled in the App Suite UI on a smartphone.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via the subject of a task.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an appointment in which the location contains JavaScript code.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via an inline binary file.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/share/?delivery=view URI.
- risk 0.40cvss 6.1epss 0.01
OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
- risk 0.40cvss 6.1epss 0.07
OX App Suite through 7.10.4 allows XSS via the app loading mechanism (the PATH_INFO to the /appsuite URI).
- risk 0.40cvss 6.1epss 0.02
OX App Suite through 7.10.2 has XSS.
Page 1 of 2