Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
open-xchange vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-37307
OX App Suite up to and including 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
5.3
CVSSv3
CVE-2022-37311
OX App Suite up to and including 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
5.4
CVSSv3
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite prior to 7.8.3-rev12 and 7.8.4 prior to 7.8.4-rev9 allows remote malicious users to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to...
Open-xchange Open-xchange Appsuite 7.8.4
Open-xchange Open-xchange Appsuite 7.8.3
Open-xchange Open-xchange Appsuite
1 EDB exploit
7.8
CVSSv3
CVE-2014-5238
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite prior to 7.4.2-rev11 and 7.6.x prior to 7.6.0-rev9 allows remote malicious users to read arbitrary files and possibly other unspecified impact via a crafted OpenDocument Text document.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.4.2
Open-xchange Open-xchange Appsuite 7.6.0
6.1
CVSSv3
CVE-2022-37310
OX App Suite up to and including 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
5.3
CVSSv3
CVE-2022-37313
OX App Suite up to and including 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
6.1
CVSSv3
CVE-2022-37309
OX App Suite up to and including 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
6.1
CVSSv3
CVE-2022-31469
OX App Suite up to and including 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.10.5
Open-xchange Open-xchange Appsuite 7.10.6
NA
CVE-2014-1679
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite prior to 7.2.2-rev31, 7.4.0 prior to 7.4.0-rev27, and 7.4.1 prior to 7.4.1-rev17 allows remote malicious users to inject arbitrary web script or HTML via the header in an attached SVG file.
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.4.0
Open-xchange Open-xchange Appsuite 7.4.1
7.5
CVSSv3
CVE-2014-5236
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite prior to 7.4.2-rev10 and 7.6.x prior to 7.6.0-rev10 allow remote malicious users to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDo...
Open-xchange Open-xchange Appsuite
Open-xchange Open-xchange Appsuite 7.4.2
Open-xchange Open-xchange Appsuite 7.6.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site scripting
CVE-2024-5158
XML external entity
CVE-2024-4262
CVE-2024-2036
CVE-2024-4985
CVE-2024-21791
remote attackers
CVE-2023-43208
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »