Перейти к содержимому
Noroxi

Записи ownCloud

169 опубликованных записей вендора owncloud.

Профиль для исследователя

Попали в KEV
2 · 1,2 %
С эксплойтом
2 · 1,2 %
Pre-auth RCE
5
С записью об исправлении
11,8 %
Медиана: публикация → KEV
510 дн.

Все записи

169 записей
  • CVE-2023-49103
    84Срочно

    An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 78 %

    owncloud · graph api21 нояб. 2023 г.

  • CVE-2023-49105
    82Срочно

    An issue was discovered in ownCloud owncloud/core before 10.13.1.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 43 %

    owncloud · owncloud server21 нояб. 2023 г.

  • CVE-2015-4716
    47В плане

    Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows,

    КритическаяCVSS 10,0Эксплойта нетEPSS 25 %

    owncloud · owncloud21 окт. 2015 г.

  • CVE-2014-2048
    40В плане

    The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatio

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    owncloud · owncloud26 мар. 2018 г.

  • CVE-2014-2052
    40В плане

    Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a de

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    owncloud · owncloud11 февр. 2020 г.

  • CVE-2021-35946
    39Наблюдать

    A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore ele

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    owncloud · owncloud7 сент. 2021 г.

  • CVE-2015-7699
    37Наблюдать

    The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to inst

    КритическаяCVSS 9,0Эксплойта нетEPSS 4 %

    owncloud · owncloud server26 окт. 2015 г.

  • CVE-2015-4718
    37Наблюдать

    The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated user

    КритическаяCVSS 9,0Эксплойта нетEPSS 3 %

    owncloud · owncloud21 окт. 2015 г.

  • CVE-2015-7698
    37Наблюдать

    icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argume

    КритическаяCVSS 9,0Эксплойта нетEPSS 2 %

    owncloud · smb21 окт. 2015 г.

  • CVE-2020-28645
    36Наблюдать

    Deleting users with certain names caused system files to be deleted.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    owncloud · owncloud9 февр. 2021 г.

  • CVE-2016-1499
    35Наблюдать

    ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information f

    ВысокаяCVSS 8,5Эксплойта нетEPSS 3 %

    owncloud · owncloud8 янв. 2016 г.

  • CVE-2021-33828
    35Наблюдать

    The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploade

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    owncloud · files antivirus15 янв. 2022 г.

  • CVE-2014-2044
    34Наблюдать

    Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to

    ВысокаяCVSS 7,5Proof of conceptEPSS 12 %

    owncloud · owncloud6 окт. 2014 г.

  • CVE-2016-9463
    33Наблюдать

    Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %

    nextcloud · nextcloud server27 мар. 2017 г.

  • CVE-2020-10252
    33Наблюдать

    An issue was discovered in ownCloud before 10.4.

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    owncloud · owncloud19 февр. 2021 г.

  • CVE-2016-7102
    33Наблюдать

    ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special p

    ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %

    owncloud · owncloud desktop client23 янв. 2017 г.

  • CVE-2015-4717
    32Наблюдать

    The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_G

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    owncloud · owncloud21 окт. 2015 г.

  • CVE-2021-44537
    32Наблюдать

    ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execut

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    owncloud · owncloud desktop client15 янв. 2022 г.

  • CVE-2014-2053
    31Наблюдать

    getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cau

    ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %

    getid3 · getid34 июн. 2014 г.

  • CVE-2012-4392
    31Наблюдать

    index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a cra

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    owncloud · owncloud server5 сент. 2012 г.

  • CVE-2015-6500
    31Наблюдать

    Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    owncloud · owncloud server26 окт. 2015 г.

  • CVE-2014-2056
    31Наблюдать

    PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    owncloud · owncloud server4 июн. 2014 г.

  • CVE-2014-2055
    31Наблюдать

    SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, ca

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    owncloud · owncloud server4 июн. 2014 г.

  • CVE-2020-28646
    31Наблюдать

    ownCloud owncloud/client before 2.7 allows DLL Injection.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    owncloud · owncloud desktop client26 февр. 2021 г.

  • CVE-2014-2054
    30Наблюдать

    PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    owncloud · owncloud server4 июн. 2014 г.