Записи ownCloud
169 опубликованных записей вендора owncloud.
Профиль для исследователя
- Попали в KEV
- 2 · 1,2 %
- С эксплойтом
- 2 · 1,2 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 11,8 %
- Медиана: публикация → KEV
- 510 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')40
- CWE-264 Permissions, Privileges, and Access Controls16
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-20 Improper Input Validation8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
169 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
84Срочно | CVE-2023-49103Готовый эксплойт | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.owncloud · graph api · CWE-200 | Высокая7,5 | KEV | 78,4 % | 21 нояб. 2023 г. |
82Срочно | CVE-2023-49105Готовый эксплойт | An issue was discovered in ownCloud owncloud/core before 10.13.1.owncloud · owncloud server · CWE-287 | Критическая9,8 | KEV | 42,9 % | 21 нояб. 2023 г. |
47В плане | CVE-2015-4716Эксплойта нет | Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, owncloud · owncloud · CWE-22 | Критическая10,0 | — | 24,8 % | 21 окт. 2015 г. |
40В плане | CVE-2014-2048Эксплойта нет | The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatioowncloud · owncloud · CWE-284 | Критическая9,8 | — | 2,6 % | 26 мар. 2018 г. |
40В плане | CVE-2014-2052Эксплойта нет | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a deowncloud · owncloud · CWE-611 | Критическая9,8 | — | 2,5 % | 11 февр. 2020 г. |
39Наблюдать | CVE-2021-35946Эксплойта нет | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore eleowncloud · owncloud · CWE-269 | Критическая9,8 | — | 1,5 % | 7 сент. 2021 г. |
37Наблюдать | CVE-2015-7699Эксплойта нет | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instowncloud · owncloud server · CWE-20 | Критическая9,0 | — | 4,0 % | 26 окт. 2015 г. |
37Наблюдать | CVE-2015-4718Эксплойта нет | The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated userowncloud · owncloud · CWE-78 | Критическая9,0 | — | 3,0 % | 21 окт. 2015 г. |
37Наблюдать | CVE-2015-7698Эксплойта нет | icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argumeowncloud · smb · CWE-78 | Критическая9,0 | — | 2,5 % | 21 окт. 2015 г. |
36Наблюдать | CVE-2020-28645Эксплойта нет | Deleting users with certain names caused system files to be deleted.owncloud · owncloud · CWE-20 | Критическая9,1 | — | 1,2 % | 9 февр. 2021 г. |
35Наблюдать | CVE-2016-1499Эксплойта нет | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information fowncloud · owncloud · CWE-200 | Высокая8,5 | — | 3,5 % | 8 янв. 2016 г. |
35Наблюдать | CVE-2021-33828Эксплойта нет | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploadeowncloud · files antivirus · CWE-434 | Высокая8,8 | — | 1,2 % | 15 янв. 2022 г. |
34Наблюдать | CVE-2014-2044Proof of concept | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to owncloud · owncloud · CWE-94 | Высокая7,5 | — | 12,4 % | 6 окт. 2014 г. |
33Наблюдать | CVE-2016-9463Эксплойта нет | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.nextcloud · nextcloud server · CWE-303 | Высокая8,1 | — | 4,1 % | 27 мар. 2017 г. |
33Наблюдать | CVE-2020-10252Эксплойта нет | An issue was discovered in ownCloud before 10.4.owncloud · owncloud · CWE-918 | Высокая8,3 | — | 1,2 % | 19 февр. 2021 г. |
33Наблюдать | CVE-2016-7102Эксплойта нет | ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special powncloud · owncloud desktop client · CWE-94 | Высокая8,4 | — | 0,5 % | 23 янв. 2017 г. |
32Наблюдать | CVE-2015-4717Эксплойта нет | The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_Gowncloud · owncloud · CWE-399 | Высокая7,8 | — | 2,8 % | 21 окт. 2015 г. |
32Наблюдать | CVE-2021-44537Эксплойта нет | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code executowncloud · owncloud desktop client · CWE-74 | Высокая7,8 | — | 2,7 % | 15 янв. 2022 г. |
31Наблюдать | CVE-2014-2053Эксплойта нет | getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caugetid3 · getid3 | Высокая7,5 | — | 4,7 % | 4 июн. 2014 г. |
31Наблюдать | CVE-2012-4392Эксплойта нет | index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a craowncloud · owncloud server · CWE-287 | Высокая7,5 | — | 2,8 % | 5 сент. 2012 г. |
31Наблюдать | CVE-2015-6500Эксплойта нет | Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directoryowncloud · owncloud server · CWE-22 | Высокая7,5 | — | 2,6 % | 26 окт. 2015 г. |
31Наблюдать | CVE-2014-2056Эксплойта нет | PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial ofowncloud · owncloud server | Высокая7,5 | — | 2,3 % | 4 июн. 2014 г. |
31Наблюдать | CVE-2014-2055Эксплойта нет | SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caowncloud · owncloud server | Высокая7,5 | — | 2,2 % | 4 июн. 2014 г. |
31Наблюдать | CVE-2020-28646Эксплойта нет | ownCloud owncloud/client before 2.7 allows DLL Injection.owncloud · owncloud desktop client · CWE-427 | Высокая7,8 | — | 0,8 % | 26 февр. 2021 г. |
30Наблюдать | CVE-2014-2054Эксплойта нет | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, owncloud · owncloud server | Высокая7,5 | — | 1,5 % | 4 июн. 2014 г. |
- CVE-2023-4910384Срочно
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 78 %owncloud · graph api21 нояб. 2023 г.
- CVE-2023-4910582Срочно
An issue was discovered in ownCloud owncloud/core before 10.13.1.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 43 %owncloud · owncloud server21 нояб. 2023 г.
- CVE-2015-471647В плане
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows,
КритическаяCVSS 10,0Эксплойта нетEPSS 25 %owncloud · owncloud21 окт. 2015 г.
- CVE-2014-204840В плане
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatio
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %owncloud · owncloud26 мар. 2018 г.
- CVE-2014-205240В плане
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a de
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %owncloud · owncloud11 февр. 2020 г.
- CVE-2021-3594639Наблюдать
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore ele
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %owncloud · owncloud7 сент. 2021 г.
- CVE-2015-769937Наблюдать
The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to inst
КритическаяCVSS 9,0Эксплойта нетEPSS 4 %owncloud · owncloud server26 окт. 2015 г.
- CVE-2015-471837Наблюдать
The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated user
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %owncloud · owncloud21 окт. 2015 г.
- CVE-2015-769837Наблюдать
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argume
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %owncloud · smb21 окт. 2015 г.
- CVE-2020-2864536Наблюдать
Deleting users with certain names caused system files to be deleted.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %owncloud · owncloud9 февр. 2021 г.
- CVE-2016-149935Наблюдать
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information f
ВысокаяCVSS 8,5Эксплойта нетEPSS 3 %owncloud · owncloud8 янв. 2016 г.
- CVE-2021-3382835Наблюдать
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploade
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %owncloud · files antivirus15 янв. 2022 г.
- CVE-2014-204434Наблюдать
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to
ВысокаяCVSS 7,5Proof of conceptEPSS 12 %owncloud · owncloud6 окт. 2014 г.
- CVE-2016-946333Наблюдать
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %nextcloud · nextcloud server27 мар. 2017 г.
- CVE-2020-1025233Наблюдать
An issue was discovered in ownCloud before 10.4.
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %owncloud · owncloud19 февр. 2021 г.
- CVE-2016-710233Наблюдать
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special p
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %owncloud · owncloud desktop client23 янв. 2017 г.
- CVE-2015-471732Наблюдать
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_G
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %owncloud · owncloud21 окт. 2015 г.
- CVE-2021-4453732Наблюдать
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execut
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %owncloud · owncloud desktop client15 янв. 2022 г.
- CVE-2014-205331Наблюдать
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cau
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %getid3 · getid34 июн. 2014 г.
- CVE-2012-439231Наблюдать
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a cra
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %owncloud · owncloud server5 сент. 2012 г.
- CVE-2015-650031Наблюдать
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %owncloud · owncloud server26 окт. 2015 г.
- CVE-2014-205631Наблюдать
PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %owncloud · owncloud server4 июн. 2014 г.
- CVE-2014-205531Наблюдать
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, ca
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %owncloud · owncloud server4 июн. 2014 г.
- CVE-2020-2864631Наблюдать
ownCloud owncloud/client before 2.7 allows DLL Injection.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %owncloud · owncloud desktop client26 февр. 2021 г.
- CVE-2014-205430Наблюдать
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %owncloud · owncloud server4 июн. 2014 г.