Ox Guard
Vendor:
First CVE: Nov 19, 2015 · Active for 10 years
11
Total CVEs
More Total CVEs than 90% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ox Guard over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2015
10 years ago
Most Recent CVE
Nov 2, 2023
999 days ago
CVE Severity & Scoring
Ox Guard11 CVEs
64%
36%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High1 (9.1%)
Unknown1 (9.1%)
User Interaction
None4 (36.4%)
Unknown1 (9.1%)
Required6 (54.5%)
Privileges Required
Low4 (36.4%)
High0 (0.0%)
None6 (54.5%)
Unknown1 (9.1%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6854MEDIUM An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. M | Dec 15, 2016 | 6.1 | 30 | NO | YES |
CVE-2015-8542HIGH An issue was discovered in Open-Xchange Guard before 2.2.0-rev8. The "getprivkeybyid" API call is used to download a PGP Private Key for a specific user after providing authenticat | Dec 15, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-10986HIGH OX Guard 2.8.0 has CSRF. | Jul 3, 2019 | 8.8 | 26 | NO | NO |
CVE-2016-6853MEDIUM An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting | Dec 15, 2016 | 6.1 | 25 | NO | YES |
CVE-2016-6851MEDIUM An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site sc | Dec 15, 2016 | 6.1 | 25 | NO | YES |
CVE-2016-4028HIGH An issue was discovered in Open-Xchange OX Guard before 2.4.0-rev8. OX Guard uses an authentication token to identify and transfer guest users' credentials. The OX Guard API acts | Dec 15, 2016 | 7.5 | 24 | NO | NO |
CVE-2020-28944HIGH OX Guard 2.10.4 and earlier allows a Denial of Service via a WKS server that responds slowly or with a large amount of data. | Apr 30, 2021 | 7.5 | 23 | NO | NO |
CVE-2020-9426MEDIUM OX Guard 2.10.3 and earlier allows XSS. | Jun 15, 2020 | 6.1 | 22 | NO | NO |
CVE-2020-9427MEDIUM OX Guard 2.10.3 and earlier allows SSRF. | Jun 15, 2020 | 5.0 | 19 | NO | NO |
CVE-2023-26456MEDIUM Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect c | Nov 2, 2023 | 5.4 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
27.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Ox Guard
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.0 | 1 | 8.8 | 0.5% | 0 | 0 |
| 2.10.7 | 1 | 5.4 | 0.4% | 0 | 0 |
| 2.10.3 | 2 | 5.5 | 1.1% | 0 | 0 |