CVE-2019-5449
- EPSS 0.3%
- Veröffentlicht 30.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:57
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
CVE-2019-5451
- EPSS 0.07%
- Veröffentlicht 30.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:44:57
Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.
CVE-2018-16463
- EPSS 0.13%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
CVE-2018-16464
- EPSS 0.22%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
CVE-2018-16465
- EPSS 0.15%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
CVE-2018-16466
- EPSS 0.13%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
CVE-2018-16467
- EPSS 0.24%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
CVE-2018-3780
- EPSS 0.54%
- Veröffentlicht 13.08.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:03
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be craf...
CVE-2018-3775
- EPSS 0.19%
- Veröffentlicht 12.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:03
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
CVE-2018-3776
- EPSS 0.55%
- Veröffentlicht 12.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:03
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.