Open-xchange
Open-xchange OX Guard: vulnerabilidades y CVE
Open-xchange OX Guard tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-26456 | Media (5.4) | 0.38% | — | 2 nov 2023 | Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts… |
| CVE-2020-28944 | Alta (7.5) | 1.6% | — | 30 abr 2021 | OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. |
| CVE-2020-9427 | Media (5) | 1.1% | — | 15 jun 2020 | OX Guard 2.10.3 and earlier allows SSRF. |
| CVE-2020-9426 | Media (6.1) | 1.2% | — | 15 jun 2020 | OX Guard 2.10.3 and earlier allows XSS. |
| CVE-2018-10986 | Alta (8.8) | 0.46% | — | 3 jul 2019 | OX Guard 2.8.0 has CSRF. |
| CVE-2016-6854 | Media (6.1) | 2.4% | — | 15 dic 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed… |
| CVE-2016-6853 | Media (6.1) | 2.4% | — | 15 dic 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific… |
| CVE-2016-6851 | Media (6.1) | 2.6% | — | 15 dic 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users… |
| CVE-2016-4028 | Alta (7.5) | 0.71% | — | 15 dic 2016 | An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts as a padding oracle by responding with… |
| CVE-2015-8542 | Alta (8.8) | 2.2% | — | 15 dic 2016 | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authentication credentials. Clients provide the… |
| CVE-2015-7385 | Media (4.3) | 2.0% | — | 19 nov 2015 | Cross-site scripting (XSS) vulnerability in Open-Xchange OX Guard before 2.0.0-rev11 allows remote attackers to inject arbitrary web script or HTML via the uid field in a PGP public key, which is not properly handled in… |