ownCloud kayıtları
owncloud üreticisine ait 169 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1,2
- Silahlaştırılmış
- 2 · %1,2
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %11,8
- Yayından KEV’e ortanca
- 510 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')40
- CWE-264 Permissions, Privileges, and Access Controls16
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-20 Improper Input Validation8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
169 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
84Hemen | CVE-2023-49103Silahlaştırılmış | An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.owncloud · graph api · CWE-200 | Yüksek7,5 | KEV | %78,4 | 21 Kas 2023 |
82Hemen | CVE-2023-49105Silahlaştırılmış | An issue was discovered in ownCloud owncloud/core before 10.13.1.owncloud · owncloud server · CWE-287 | Kritik9,8 | KEV | %42,9 | 21 Kas 2023 |
47Planlayın | CVE-2015-4716İstismar yok | Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, owncloud · owncloud · CWE-22 | Kritik10,0 | — | %24,8 | 21 Eki 2015 |
40Planlayın | CVE-2014-2048İstismar yok | The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatioowncloud · owncloud · CWE-284 | Kritik9,8 | — | %2,6 | 26 Mar 2018 |
40Planlayın | CVE-2014-2052İstismar yok | Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a deowncloud · owncloud · CWE-611 | Kritik9,8 | — | %2,5 | 11 Şub 2020 |
39İzleyin | CVE-2021-35946İstismar yok | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore eleowncloud · owncloud · CWE-269 | Kritik9,8 | — | %1,5 | 7 Eyl 2021 |
37İzleyin | CVE-2015-7699İstismar yok | The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instowncloud · owncloud server · CWE-20 | Kritik9,0 | — | %4,0 | 26 Eki 2015 |
37İzleyin | CVE-2015-4718İstismar yok | The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated userowncloud · owncloud · CWE-78 | Kritik9,0 | — | %3,0 | 21 Eki 2015 |
37İzleyin | CVE-2015-7698İstismar yok | icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argumeowncloud · smb · CWE-78 | Kritik9,0 | — | %2,5 | 21 Eki 2015 |
36İzleyin | CVE-2020-28645İstismar yok | Deleting users with certain names caused system files to be deleted.owncloud · owncloud · CWE-20 | Kritik9,1 | — | %1,2 | 9 Şub 2021 |
35İzleyin | CVE-2016-1499İstismar yok | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information fowncloud · owncloud · CWE-200 | Yüksek8,5 | — | %3,5 | 8 Oca 2016 |
35İzleyin | CVE-2021-33828İstismar yok | The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploadeowncloud · files antivirus · CWE-434 | Yüksek8,8 | — | %1,2 | 15 Oca 2022 |
34İzleyin | CVE-2014-2044Kavram kanıtı | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to owncloud · owncloud · CWE-94 | Yüksek7,5 | — | %12,4 | 6 Eki 2014 |
33İzleyin | CVE-2016-9463İstismar yok | Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.nextcloud · nextcloud server · CWE-303 | Yüksek8,1 | — | %4,1 | 27 Mar 2017 |
33İzleyin | CVE-2020-10252İstismar yok | An issue was discovered in ownCloud before 10.4.owncloud · owncloud · CWE-918 | Yüksek8,3 | — | %1,2 | 19 Şub 2021 |
33İzleyin | CVE-2016-7102İstismar yok | ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special powncloud · owncloud desktop client · CWE-94 | Yüksek8,4 | — | %0,5 | 23 Oca 2017 |
32İzleyin | CVE-2015-4717İstismar yok | The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_Gowncloud · owncloud · CWE-399 | Yüksek7,8 | — | %2,8 | 21 Eki 2015 |
32İzleyin | CVE-2021-44537İstismar yok | ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code executowncloud · owncloud desktop client · CWE-74 | Yüksek7,8 | — | %2,7 | 15 Oca 2022 |
31İzleyin | CVE-2014-2053İstismar yok | getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caugetid3 · getid3 | Yüksek7,5 | — | %4,7 | 4 Haz 2014 |
31İzleyin | CVE-2012-4392İstismar yok | index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a craowncloud · owncloud server · CWE-287 | Yüksek7,5 | — | %2,8 | 5 Eyl 2012 |
31İzleyin | CVE-2015-6500İstismar yok | Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directoryowncloud · owncloud server · CWE-22 | Yüksek7,5 | — | %2,6 | 26 Eki 2015 |
31İzleyin | CVE-2014-2056İstismar yok | PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial ofowncloud · owncloud server | Yüksek7,5 | — | %2,3 | 4 Haz 2014 |
31İzleyin | CVE-2014-2055İstismar yok | SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, caowncloud · owncloud server | Yüksek7,5 | — | %2,2 | 4 Haz 2014 |
31İzleyin | CVE-2020-28646İstismar yok | ownCloud owncloud/client before 2.7 allows DLL Injection.owncloud · owncloud desktop client · CWE-427 | Yüksek7,8 | — | %0,8 | 26 Şub 2021 |
30İzleyin | CVE-2014-2054İstismar yok | PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, owncloud · owncloud server | Yüksek7,5 | — | %1,5 | 4 Haz 2014 |
- CVE-2023-4910384Hemen
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %78owncloud · graph api21 Kas 2023
- CVE-2023-4910582Hemen
An issue was discovered in ownCloud owncloud/core before 10.13.1.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %43owncloud · owncloud server21 Kas 2023
- CVE-2015-471647Planlayın
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows,
KritikCVSS 10,0İstismar yokEPSS %25owncloud · owncloud21 Eki 2015
- CVE-2014-204840Planlayın
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatio
KritikCVSS 9,8İstismar yokEPSS %3owncloud · owncloud26 Mar 2018
- CVE-2014-205240Planlayın
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a de
KritikCVSS 9,8İstismar yokEPSS %2owncloud · owncloud11 Şub 2020
- CVE-2021-3594639İzleyin
A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore ele
KritikCVSS 9,8İstismar yokEPSS %1owncloud · owncloud7 Eyl 2021
- CVE-2015-769937İzleyin
The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to inst
KritikCVSS 9,0İstismar yokEPSS %4owncloud · owncloud server26 Eki 2015
- CVE-2015-471837İzleyin
The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated user
KritikCVSS 9,0İstismar yokEPSS %3owncloud · owncloud21 Eki 2015
- CVE-2015-769837İzleyin
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argume
KritikCVSS 9,0İstismar yokEPSS %2owncloud · smb21 Eki 2015
- CVE-2020-2864536İzleyin
Deleting users with certain names caused system files to be deleted.
KritikCVSS 9,1İstismar yokEPSS %1owncloud · owncloud9 Şub 2021
- CVE-2016-149935İzleyin
ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information f
YüksekCVSS 8,5İstismar yokEPSS %3owncloud · owncloud8 Oca 2016
- CVE-2021-3382835İzleyin
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploade
YüksekCVSS 8,8İstismar yokEPSS %1owncloud · files antivirus15 Oca 2022
- CVE-2014-204434İzleyin
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to
YüksekCVSS 7,5Kavram kanıtıEPSS %12owncloud · owncloud6 Eki 2014
- CVE-2016-946333İzleyin
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.
YüksekCVSS 8,1İstismar yokEPSS %4nextcloud · nextcloud server27 Mar 2017
- CVE-2020-1025233İzleyin
An issue was discovered in ownCloud before 10.4.
YüksekCVSS 8,3İstismar yokEPSS %1owncloud · owncloud19 Şub 2021
- CVE-2016-710233İzleyin
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special p
YüksekCVSS 8,4İstismar yokEPSS %1owncloud · owncloud desktop client23 Oca 2017
- CVE-2015-471732İzleyin
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_G
YüksekCVSS 7,8İstismar yokEPSS %3owncloud · owncloud21 Eki 2015
- CVE-2021-4453732İzleyin
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execut
YüksekCVSS 7,8İstismar yokEPSS %3owncloud · owncloud desktop client15 Oca 2022
- CVE-2014-205331İzleyin
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cau
YüksekCVSS 7,5İstismar yokEPSS %5getid3 · getid34 Haz 2014
- CVE-2012-439231İzleyin
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a cra
YüksekCVSS 7,5İstismar yokEPSS %3owncloud · owncloud server5 Eyl 2012
- CVE-2015-650031İzleyin
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory
YüksekCVSS 7,5İstismar yokEPSS %3owncloud · owncloud server26 Eki 2015
- CVE-2014-205631İzleyin
PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of
YüksekCVSS 7,5İstismar yokEPSS %2owncloud · owncloud server4 Haz 2014
- CVE-2014-205531İzleyin
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, ca
YüksekCVSS 7,5İstismar yokEPSS %2owncloud · owncloud server4 Haz 2014
- CVE-2020-2864631İzleyin
ownCloud owncloud/client before 2.7 allows DLL Injection.
YüksekCVSS 7,8İstismar yokEPSS %1owncloud · owncloud desktop client26 Şub 2021
- CVE-2014-205430İzleyin
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,
YüksekCVSS 7,5İstismar yokEPSS %2owncloud · owncloud server4 Haz 2014