Vulnerabilities > Open Xchange > Open Xchange Appsuite Backend > 7.10.6

DATE CVE VULNERABILITY TITLE RISK
2023-06-20 CVE-2023-26434 Unspecified vulnerability in Open-Xchange Appsuite Backend
When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes.
network
low complexity
open-xchange
4.3
2023-06-20 CVE-2023-26435 Server-Side Request Forgery (SSRF) vulnerability in Open-Xchange Appsuite Backend
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents.
network
low complexity
open-xchange CWE-918
5.0
2023-06-20 CVE-2023-26436 Deserialization of Untrusted Data vulnerability in Open-Xchange Appsuite Backend
Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization.
low complexity
open-xchange CWE-502
8.8