← Back

CVE-2014-5236

nvd nist
Published: Jan 31, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files via a full pathname in a crafted (1) OLE Object or (2) image in an OpenDocument text file.

Affected (21)

1 product
Open Xchange Appsuite
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Open Xchange
Up to 7.4.1
Version 7.4.2
Version 7.4.2 revision10
Version 7.4.2 revision1
Version 7.4.2 revision2
Version 7.4.2 revision3
Version 7.4.2 revision4
Version 7.4.2 revision5
Version 7.4.2 revision6
Version 7.4.2 revision7
Version 7.4.2 revision8
Version 7.4.2 revision9
Version 7.6.0
Version 7.6.0 revision1
Version 7.6.0 revision2
Version 7.6.0 revision3
Version 7.6.0 revision4
Version 7.6.0 revision5
Version 7.6.0 revision6
Version 7.6.0 revision7
Version 7.6.0 revision8

References (6)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.