Vulnerabilities
Vulnerable Software
Processing time of drive search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing of user-defined drive search expressions is not limited No publicly available exploits are known.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-02-12
Processing of user-defined mail search expressions is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of mail search expressions now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-02-12
User ID references at mentions in document comments were not correctly sanitized. Script code could be injected to a users session when working with a malicious document. Please deploy the provided updates and patch releases. User-defined content like comments and mentions are now filtered to avoid potentially malicious content. No publicly available exploits are known.
CVSS Score
6.1
EPSS Score
0.003
Published
2024-02-12
Processing of CID references at E-Mail can be abused to inject malicious script code that passes the sanitization engine. Malicious script code could be injected to a users sessions when interacting with E-Mails. Please deploy the provided updates and patch releases. CID handing has been improved and resulting content is checked for malicious content. No publicly available exploits are known.
CVSS Score
7.1
EPSS Score
0.002
Published
2024-02-12
Processing of user-defined DAV user-agent strings is not limited. Availability of OX App Suite could be reduced due to high processing load. Please deploy the provided updates and patch releases. Processing time of DAV user-agents now gets monitored, and the related request is terminated if a resource threshold is reached. No publicly available exploits are known.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-02-12
OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
CVSS Score
5.4
EPSS Score
0.006
Published
2022-12-26
OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HTML e-mail message.
CVSS Score
5.4
EPSS Score
0.006
Published
2022-12-26


Contact Us

Shodan ® - All rights reserved