Filtered by vendor Owncloud
Subscriptions
Total
168 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-28645 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 9.1 Critical |
Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6. | ||||
CVE-2020-28644 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 4.3 Medium |
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6. | ||||
CVE-2020-16255 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 6.1 Medium |
ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.' | ||||
CVE-2020-16144 | 1 Owncloud | 1 Files Antivirus | 2024-11-21 | 5.7 Medium |
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud. | ||||
CVE-2020-10254 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 5.9 Medium |
An issue was discovered in ownCloud before 10.4. An attacker can bypass authentication on a password-protected image by displaying its preview. | ||||
CVE-2020-10252 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 8.3 High |
An issue was discovered in ownCloud before 10.4. Because of an SSRF issue (via the apps/files_sharing/external remote parameter), an authenticated attacker can interact with local services blindly (aka Blind SSRF) or conduct a Denial Of Service attack. | ||||
CVE-2014-2048 | 1 Owncloud | 1 Owncloud | 2024-11-21 | N/A |
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation. | ||||
CVE-2014-1665 | 1 Owncloud | 1 Owncloud | 2024-11-21 | N/A |
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file. |