Vulnerabilities in Open-Xchange GmbH

72 results
Vexday analysis

Open-Xchange GmbH apresenta 47 vulnerabilidades catalogadas, predominantemente de injeção de script (CWE-79), sem críticas ou exploração ativa conhecida. Cinco vulnerabilidades foram publicadas nos últimos 90 dias, indicando risco moderado e constante que requer monitoramento contínuo, especialmente em ambientes que lidam com dados sensíveis.

CVE-2023-41704HIGHProcessing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script cEPSS 0.5%CVE-2023-41703MEDIUMUser ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when workEPSS 0.5%CVE-2024-23188MEDIUMMaliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. CoEPSS 0.5%CVE-2024-23191MEDIUMUpsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To expEPSS 0.5%CVE-2024-23190MEDIUMUpsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit thisEPSS 0.5%CVE-2024-23187MEDIUMContent-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. AttEPSS 0.5%CVE-2026-42391HIGHAn unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPEPSS 0.5%CVE-2026-33605HIGHAn unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running iEPSS 0.5%CVE-2023-41708MEDIUMReferences to the "app loader" functionality could contain redirects to unexpected locations. Attackers could forge app references that bypaEPSS 0.5%CVE-2026-27852HIGHAn attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parametersEPSS 0.5%CVE-2025-59028MEDIUMWhen sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentication sessions to faiEPSS 0.4%CVE-2023-29052MEDIUMUsers were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. AttackEPSS 0.4%CVE-2023-41710MEDIUMUser-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. AttackeEPSS 0.4%CVE-2026-27856HIGHDoveadm credentials are verified using direct comparison which is susceptible to timing oracle attack. An attacker can use this to determineEPSS 0.4%CVE-2026-40016MEDIUMAttacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits for Sieve up to 130 EPSS 0.4%CVE-2026-0394MEDIUMWhen dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added EPSS 0.4%CVE-2026-73209MEDIUMAn attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. TheEPSS 0.4%CVE-2026-52687MEDIUMAn attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a largeEPSS 0.4%CVE-2024-25582MEDIUMModule savepoints could be abused to inject references to malicious code delivered through the same domain. Attackers could perform maliciouEPSS 0.4%CVE-2026-27859MEDIUMA mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably formatted mail message caEPSS 0.4%