Skip to main content

Vendor archive

open-xchange CVEs

Beta · best-effort

272 CVEs tagged to vendor open-xchange10 Critical, 36 High, 213 Medium, 13 Low, 0 Unrated.

CVE-2023-26442

Published Aug 2, 2023

In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricte…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26440

Published Aug 2, 2023

The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26439

Published Aug 2, 2023

The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a l…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26430

Published Aug 2, 2023

Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEVE extension that are not allowed by A…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26435

Published Jun 20, 2023

It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topolog…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26434

Published Jun 20, 2023

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26433

Published Jun 20, 2023

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26432

Published Jun 20, 2023

When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26431

Published Jun 20, 2023

IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26429

Published Jun 20, 2023

Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26428

Published Jun 20, 2023

Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24605

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 does not enforce 2FA for all endpoints, e.g., reading from a drive, reading contact data, and renaming tokens.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24604

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 does not check HTTP header lengths when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of head…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24603

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 does not check size limits when downloading, e.g., potentially allowing a crafted iCal feed to provide an unlimited amount of data.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24602

Published May 29, 2023

OX App Suite before frontend 7.10.6-rev24 allows XSS via data to the Tumblr portal widget, such as a post title.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24601

Published May 29, 2023

OX App Suite before frontend 7.10.6-rev24 allows XSS via a non-app deeplink such as the jslob API's registry sub-tree.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24600

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 allows authenticated users to bypass access controls (for reading contacts) via a move to their own address book.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24599

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 allows authenticated users to change the appointments of arbitrary users via conflicting ID numbers, aka "ID confusion."

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24598

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24597

Published May 29, 2023

OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 272 CVEsPage 3 of 11