CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian MozillaOpen Xchange4Debian Linux FirefoxOpen Xchange Appsuite Frontend+1 moreJun 17, 2026 May 14, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering...Show more |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering u...Show more |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijack...Show more |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed withi...Show more |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unw...Show more |
1Open Xchange 1Open Xchange Appsuite Frontend Jun 17, 2026 Aug 2, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead t...Show more |
1Open Xchange 4Documentconverter Api Office WebOpen Xchange Appsuite Backend+1 moreMay 13, 2026 Mar 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7....Show more |