CVE-2024-4367
- EPSS 37.17%
- Veröffentlicht 14.05.2024 18:15:12
- Zuletzt bearbeitet 24.04.2025 19:15:46
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2023-26448
- EPSS 0.08%
- Veröffentlicht 02.08.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:28
Custom log-in and log-out locations are used-defined as jslob but were not checked to contain malicious protocol handlers. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted act...
CVE-2023-26449
- EPSS 0.11%
- Veröffentlicht 02.08.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:28
The "OX Chat" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web in...
CVE-2023-26450
- EPSS 0.11%
- Veröffentlicht 02.08.2023 13:15:11
- Zuletzt bearbeitet 21.11.2024 07:51:29
The "OX Count" web service did not specify a media-type when processing responses by external resources. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web i...
CVE-2023-26445
- EPSS 0.06%
- Veröffentlicht 02.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:51:28
Frontend themes are defined by user-controllable jslob settings and could point to a malicious resource which gets processed during login. Malicious script code can be executed within the victims context. This can lead to session hijacking or trigger...
CVE-2023-26446
- EPSS 0.08%
- Veröffentlicht 02.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:51:28
The users clientID at "application passwords" was not sanitized or escaped before being added to DOM. Malicious script code can be executed within the victims context. This can lead to session hijacking or triggering unwanted actions via the web inte...
CVE-2023-26447
- EPSS 0.08%
- Veröffentlicht 02.08.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:51:28
The "upsell" widget for the portal allows to specify a product description. This description taken from a user-controllable jslob did not get escaped before being added to DOM. Malicious script code can be executed within the victims context. This ca...
CVE-2016-6846
- EPSS 0.3%
- Veröffentlicht 29.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office ...