CVE-2016-9461
- EPSS 0.76%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticate...
CVE-2016-9462
- EPSS 0.46%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thu...
CVE-2016-9463
- EPSS 3.86%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenti...
CVE-2016-9464
- EPSS 0.29%
- Veröffentlicht 28.03.2017 02:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users...
CVE-2016-7419
- EPSS 0.2%
- Veröffentlicht 17.09.2016 21:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.