Nextcloud

Nextcloud Server

175 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 05.04.2017 20:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a ...

  • EPSS 0.21%
  • Published 05.04.2017 20:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files...

  • EPSS 0.61%
  • Published 05.04.2017 20:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

  • EPSS 0.25%
  • Published 05.04.2017 20:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota....

  • EPSS 0.54%
  • Published 05.04.2017 20:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of inf...

Exploit
  • EPSS 0.5%
  • Published 28.03.2017 02:59:01
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. D...

Exploit
  • EPSS 0.46%
  • Published 28.03.2017 02:59:01
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where ...

Exploit
  • EPSS 1.05%
  • Published 28.03.2017 02:59:01
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a ...

Exploit
  • EPSS 0.3%
  • Published 28.03.2017 02:59:01
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential mi...

Exploit
  • EPSS 0.49%
  • Published 28.03.2017 02:59:00
  • Last modified 20.04.2025 01:37:25

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user....