Vulnerability index

Browse CVEs

94 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Owncloud Server HIGH 7.5
CVE-2014-2056

PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service,…

Fix: after 5.0.14
Fix from $1,950 2014-06-04
Owncloud HIGH 7.5
CVE-2014-3834

ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access the contacts of other users v…

Fix: after 6.0.2
Fix from $1,950 2014-06-04
Owncloud MEDIUM 6.8
CVE-2014-3836

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud Server before 6.0.3 allow remote attackers to hijack the authentication of use…

Fix: after 6.0.2
Fix from $1,600 2014-06-04
Owncloud Server MEDIUM 5.5
CVE-2014-3835

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated …

Fix: after 5.0.15
Fix from $1,600 2014-06-04
Owncloud Server HIGH 7.5
CVE-2014-2053

getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a deni…

Fix: after 5.0.14
Fix from $1,950 2014-06-04
Owncloud Server HIGH 7.5
CVE-2014-2054

PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which all…

Fix: after 5.0.14
Fix from $1,950 2014-06-04
Owncloud MEDIUM 5.0
CVE-2013-1941

The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation o…

Fix: after 4.0.13
Fix from $1,600 2014-06-04
Owncloud MEDIUM 6.5
CVE-2013-0303

Unspecified vulnerability in core/ajax/translations.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute…

Fix: after 4.0.11
Fix from $1,600 2014-03-24
Owncloud MEDIUM 6.5
CVE-2013-7344

Unspecified vulnerability in core/settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrar…

Fix: after 4.0.11
Fix from $1,600 2014-03-24
Owncloud MEDIUM 6.8
CVE-2013-0299

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote attackers to hijack the auth…

Fix: after 4.0.11
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 6.8
CVE-2013-0300

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of user…

Mitigation only
Fix from $1,600 2014-03-14
Owncloud MEDIUM 6.8
CVE-2013-0301

Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijac…

Fix: after 4.0.11
Fix from $1,600 2014-03-14
Owncloud MEDIUM 6.8
CVE-2014-2047

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote att…

Fix: after 6.0.1
Fix from $1,600 2014-03-14
Owncloud MEDIUM 6.5
CVE-2013-2048

ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified …

Fix: after 5.0.5
Fix from $1,600 2014-03-14
Owncloud MEDIUM 5.8
CVE-2013-2044

Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites a…

Fix: after 5.0.5
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 5.0
CVE-2013-2086

The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an u…

Patch available
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 5.0
CVE-2014-2049

The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified v…

Fix: after 5.0.14
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 6.5
CVE-2013-1850

Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x b…

Fix: after 4.0.12
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 5.0
CVE-2013-1939

The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not …

Fix: 1.6.9 / 1.7.7+
Fix from $1,600 2014-03-14
Owncloud MEDIUM 6.5
CVE-2013-1893

SQL injection vulnerability in addressbookprovider.php in ownCloud Server before 5.0.1 allows remote authenticated users to execute arbitrary SQL com…

Fix: after 5.0.0
Fix from $1,600 2014-03-09
Owncloud Server MEDIUM 6.5
CVE-2013-2045

SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands v…

Mitigation only
Fix from $1,600 2014-03-09
Owncloud Server MEDIUM 6.5
CVE-2013-2046

SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to exe…

Mitigation only
Fix from $1,600 2014-03-09
Owncloud MEDIUM 6.8
CVE-2013-6403

The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.

Fix: after 5.0.12
Fix from $1,600 2013-12-24
Owncloud MEDIUM 6.5
CVE-2012-5609

Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by upl…

Fix: after 4.5.1
Fix from $1,600 2012-12-18
Owncloud MEDIUM 6.5
CVE-2012-5610

Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute…

Fix: after 4.0.8
Fix from $1,600 2012-12-18
Owncloud MEDIUM 5.0
CVE-2012-5607

The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers …

Fix: after 4.0.8
Fix from $1,600 2012-12-18
Owncloud MEDIUM 6.8
CVE-2012-4753

Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.5 allow remote attackers to hijack the authentication of unspecifie…

Fix: after 4.0.4
Fix from $1,600 2012-09-05
Owncloud MEDIUM 5.0
CVE-2012-4752

appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unsp…

Fix: after 4.0.5
Fix from $1,600 2012-09-05
Owncloud Server HIGH 7.5
CVE-2012-4392

index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_t…

Patch available
Fix from $1,950 2012-09-05
Owncloud MEDIUM 6.8
CVE-2012-4389

Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.7 allows remote attackers to execute arbitrary code by uploading a craft…

Fix: after 4.0.6
Fix from $1,600 2012-09-05