İçeriğe atla
Noroxi

ownCloud kayıtları

owncloud üreticisine ait 169 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %1,2
Silahlaştırılmış
2 · %1,2
Pre-auth RCE
5
Düzeltme kaydı olan
%11,8
Yayından KEV’e ortanca
510 gün

Tüm kayıtlar

169 kayıt
  • An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %78

    owncloud · graph api21 Kas 2023

  • An issue was discovered in ownCloud owncloud/core before 10.13.1.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %43

    owncloud · owncloud server21 Kas 2023

  • CVE-2015-4716
    47Planlayın

    Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows,

    KritikCVSS 10,0İstismar yokEPSS %25

    owncloud · owncloud21 Eki 2015

  • CVE-2014-2048
    40Planlayın

    The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementatio

    KritikCVSS 9,8İstismar yokEPSS %3

    owncloud · owncloud26 Mar 2018

  • CVE-2014-2052
    40Planlayın

    Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a de

    KritikCVSS 9,8İstismar yokEPSS %2

    owncloud · owncloud11 Şub 2020

  • CVE-2021-35946
    39İzleyin

    A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissions and therefore ele

    KritikCVSS 9,8İstismar yokEPSS %1

    owncloud · owncloud7 Eyl 2021

  • CVE-2015-7699
    37İzleyin

    The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to inst

    KritikCVSS 9,0İstismar yokEPSS %4

    owncloud · owncloud server26 Eki 2015

  • CVE-2015-4718
    37İzleyin

    The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated user

    KritikCVSS 9,0İstismar yokEPSS %3

    owncloud · owncloud21 Eki 2015

  • CVE-2015-7698
    37İzleyin

    icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argume

    KritikCVSS 9,0İstismar yokEPSS %2

    owncloud · smb21 Eki 2015

  • CVE-2020-28645
    36İzleyin

    Deleting users with certain names caused system files to be deleted.

    KritikCVSS 9,1İstismar yokEPSS %1

    owncloud · owncloud9 Şub 2021

  • CVE-2016-1499
    35İzleyin

    ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information f

    YüksekCVSS 8,5İstismar yokEPSS %3

    owncloud · owncloud8 Oca 2016

  • CVE-2021-33828
    35İzleyin

    The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploade

    YüksekCVSS 8,8İstismar yokEPSS %1

    owncloud · files antivirus15 Oca 2022

  • CVE-2014-2044
    34İzleyin

    Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to

    YüksekCVSS 7,5Kavram kanıtıEPSS %12

    owncloud · owncloud6 Eki 2014

  • CVE-2016-9463
    33İzleyin

    Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.

    YüksekCVSS 8,1İstismar yokEPSS %4

    nextcloud · nextcloud server27 Mar 2017

  • CVE-2020-10252
    33İzleyin

    An issue was discovered in ownCloud before 10.4.

    YüksekCVSS 8,3İstismar yokEPSS %1

    owncloud · owncloud19 Şub 2021

  • CVE-2016-7102
    33İzleyin

    ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special p

    YüksekCVSS 8,4İstismar yokEPSS %1

    owncloud · owncloud desktop client23 Oca 2017

  • CVE-2015-4717
    32İzleyin

    The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_G

    YüksekCVSS 7,8İstismar yokEPSS %3

    owncloud · owncloud21 Eki 2015

  • CVE-2021-44537
    32İzleyin

    ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execut

    YüksekCVSS 7,8İstismar yokEPSS %3

    owncloud · owncloud desktop client15 Oca 2022

  • CVE-2014-2053
    31İzleyin

    getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cau

    YüksekCVSS 7,5İstismar yokEPSS %5

    getid3 · getid34 Haz 2014

  • CVE-2012-4392
    31İzleyin

    index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a cra

    YüksekCVSS 7,5İstismar yokEPSS %3

    owncloud · owncloud server5 Eyl 2012

  • CVE-2015-6500
    31İzleyin

    Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory

    YüksekCVSS 7,5İstismar yokEPSS %3

    owncloud · owncloud server26 Eki 2015

  • CVE-2014-2056
    31İzleyin

    PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of

    YüksekCVSS 7,5İstismar yokEPSS %2

    owncloud · owncloud server4 Haz 2014

  • CVE-2014-2055
    31İzleyin

    SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, ca

    YüksekCVSS 7,5İstismar yokEPSS %2

    owncloud · owncloud server4 Haz 2014

  • CVE-2020-28646
    31İzleyin

    ownCloud owncloud/client before 2.7 allows DLL Injection.

    YüksekCVSS 7,8İstismar yokEPSS %1

    owncloud · owncloud desktop client26 Şub 2021

  • CVE-2014-2054
    30İzleyin

    PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml,

    YüksekCVSS 7,5İstismar yokEPSS %2

    owncloud · owncloud server4 Haz 2014