Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Owncloud MEDIUM 5.4
CVE-2014-1665

Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the fi…

Fix: 6.0.1+
Fix from $1,600 2018-03-20
Owncloud MEDIUM 6.5
CVE-2017-9340

An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.

Fix: 10.0.2+
Fix from $1,600 2017-07-17
Owncloud MEDIUM 6.1
CVE-2017-8896

ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting co…

Fix: 10.0.2+
Fix from $1,600 2017-07-17
Owncloud MEDIUM 5.4
CVE-2017-9338

Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.…

Fix: 8.2.12 / 9.0.10+
Fix from $1,600 2017-07-17
Owncloud MEDIUM 5.3
CVE-2017-9339

A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially …

Fix: 10.0.2+
Fix from $1,600 2017-07-17
Owncloud MEDIUM 6.5
CVE-2017-5867

ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of …

Fix: after 8.1.10
Fix from $1,600 2017-03-03
Owncloud Desktop Client HIGH 8.4
CVE-2016-7102

ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in t…

Fix: after 2.2.2
Fix from $1,950 2017-01-23
Owncloud MEDIUM 5.9
CVE-2016-5876

ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct…

Fix: after 8.2.5
Fix from $1,600 2017-01-23
Owncloud HIGH 8.5
CVE-2016-1499

ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a dir…

Fix: after 8.0.9
Fix from $1,950 2016-01-08
Owncloud MEDIUM 6.1
CVE-2016-1498

Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before …

Fix: after 7.0.11
Fix from $1,600 2016-01-08
Owncloud Client MEDIUM 5.0
CVE-2015-5955

ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain s…

Fix: 3.4.4+
Fix from $1,600 2015-10-29
Owncloud Server HIGH 9.0
CVE-2015-7699

The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate a…

Patch available
Fix from $1,950 2015-10-26
Owncloud Desktop Client MEDIUM 5.1
CVE-2015-7298

ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of erro…

Fix: after 2.0.0
Fix from $1,600 2015-10-26
Owncloud Server HIGH 7.5
CVE-2015-6500

Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents…

Mitigation only
Fix from $1,950 2015-10-26
Smb HIGH 9.0
CVE-2015-7698

icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the…

Fix: after 8.1.1
Fix from $1,950 2015-10-21
Owncloud HIGH 9.0
CVE-2015-4718

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to exec…

Fix: after 6.0.7
Fix from $1,950 2015-10-21
Owncloud HIGH 7.8
CVE-2015-4717

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parame…

Fix: after 6.0.7
Fix from $1,950 2015-10-21
Owncloud HIGH 10.0
CVE-2015-4716EPSS 25%

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows re…

Fix: after 7.0.5
Fix from $1,950 2015-10-21
Owncloud Server MEDIUM 6.0
CVE-2015-3013

ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbit…

Fix: 5.0.19 / 6.0.7+
Fix from $1,600 2015-05-08
Owncloud MEDIUM 5.0
CVE-2014-9048

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the password-protection for shar…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9046

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrar…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9045

The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requ…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud Server MEDIUM 5.0
CVE-2014-9044

Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatena…

Mitigation only
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9043

The user_ldap (aka LDAP user and group backend) application in ownCloud before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud MEDIUM 6.8
CVE-2014-9041

The import functionality in the bookmarks application in ownCloud server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 does not validate CSRF…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud HIGH 7.5
CVE-2014-2044EPSS 12%

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass in…

Fix: after 4.5.13
Fix from $1,950 2014-10-06
Owncloud Server MEDIUM 6.8
CVE-2014-4929

Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include…

Fix: after 5.0.16
Fix from $1,600 2014-08-20
Owncloud Server HIGH 7.5
CVE-2014-2051

ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstr…

Fix: after 5.0.14
Fix from $1,950 2014-06-05
Owncloud MEDIUM 5.0
CVE-2013-0302

Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via unspecified vectors related to…

Fix: after 4.0.11
Fix from $1,600 2014-06-05
Owncloud Server HIGH 7.5
CVE-2014-2055

SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a den…

Fix: after 5.0.14
Fix from $1,950 2014-06-04