CVE-2014-1679
- EPSS 0.29%
- Published 05.01.2015 20:59:00
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite before 7.2.2-rev31, 7.4.0 before 7.4.0-rev27, and 7.4.1 before 7.4.1-rev17 allows remote attackers to inject arbitrary web script or HTML via the header in an attached SVG file.
- EPSS 0.18%
- Published 27.12.2014 18:59:05
- Last modified 12.04.2025 10:46:40
The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote aut...
CVE-2014-7871
- EPSS 0.31%
- Published 21.11.2014 15:59:02
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.
CVE-2014-5234
- EPSS 0.3%
- Published 17.09.2014 14:55:03
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.
CVE-2014-5235
- EPSS 0.3%
- Published 17.09.2014 14:55:03
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via vectors related to unspecified fields in RSS fee...
CVE-2014-2391
- EPSS 0.23%
- Published 24.04.2014 05:06:05
- Last modified 12.04.2025 10:46:40
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid passwo...
CVE-2014-2392
- EPSS 0.23%
- Published 24.04.2014 05:06:05
- Last modified 12.04.2025 10:46:40
The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) ...
CVE-2014-2393
- EPSS 0.23%
- Published 24.04.2014 05:06:05
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the...
CVE-2014-2077
- EPSS 0.26%
- Published 20.03.2014 16:55:16
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the ari...
- EPSS 0.45%
- Published 26.01.2014 20:55:05
- Last modified 11.04.2025 00:51:21
XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder and the WebDAV interface. NO...