Vulnerabilidades en Open-Xchange GmbH

72 resultados
Análisis Vexday

Open-Xchange GmbH apresenta 47 vulnerabilidades catalogadas, predominantemente de injeção de script (CWE-79), sem críticas ou exploração ativa conhecida. Cinco vulnerabilidades foram publicadas nos últimos 90 dias, indicando risco moderado e constante que requer monitoramento contínuo, especialmente em ambientes que lidam com dados sensíveis.

CVE-2026-33606MEDIUMMail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync witEPSS 0.2%CVE-2026-42395MEDIUMA host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following logEPSS 0.2%CVE-2026-33603MEDIUMAttacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This requires that the atEPSS 0.2%CVE-2026-40205MEDIUMAn attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is requiEPSS 0.2%CVE-2026-40204LOWNone None None No publicly available exploits are known.EPSS 0.2%CVE-2025-59025MEDIUMMalicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, includiEPSS 0.2%CVE-2026-42393LOWThe comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An attEPSS 0.2%CVE-2024-25584MEDIUMDovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to cEPSS 0.2%CVE-2025-30190MEDIUMMalicious content at office documents can be used to inject script code when editing a document. Unintended actions can be executed in the cEPSS 0.2%CVE-2025-30186MEDIUMMalicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be exEPSS 0.2%CVE-2025-59026MEDIUMMalicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintended actions can be exEPSS 0.2%CVE-2025-30191MEDIUMMalicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensEPSS 0.2%