CVE-2017-0888
- EPSS 0.54%
- Veröffentlicht 05.04.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of inf...
CVE-2016-9465
- EPSS 0.5%
- Veröffentlicht 28.03.2017 02:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image export functionality as implemented in Nextcloud/ownCloud allows the download of images stored within a vCard. D...
CVE-2016-9466
- EPSS 0.46%
- Veröffentlicht 28.03.2017 02:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery app was not properly sanitizing exception messages from the Nextcloud/ownCloud server. Due to an endpoint where ...
CVE-2016-9467
- EPSS 1.05%
- Veröffentlicht 28.03.2017 02:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a ...
CVE-2016-9468
- EPSS 0.28%
- Veröffentlicht 28.03.2017 02:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential mi...
CVE-2016-9459
- EPSS 0.49%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a local XSS. The download log functionality in the admin screen is delivering the log in JSON format to the end-user....
CVE-2016-9461
- EPSS 0.76%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticate...
CVE-2016-9462
- EPSS 0.46%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thu...
CVE-2016-9463
- EPSS 3.86%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenti...
CVE-2016-9464
- EPSS 0.29%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users...