The Ox Project maintains a focused open-source collaboration and messaging platform, with vulnerability disclosures concentrated in its core Ox product around input-validation and out-of-bounds-read weaknesses typical of server-side parsing and protocol handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ox Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15928HIGH In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error m | Oct 27, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-16229MEDIUM In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse. | Feb 26, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ox Project.
Media articles that mention a CVE ID that affects a product developed by Ox Project — matched by CVE ID, not by vendor name.