CVE-2022-24889
- EPSS 0.16%
- Veröffentlicht 27.04.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:19
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they ...
CVE-2022-24886
- EPSS 0.08%
- Veröffentlicht 27.04.2022 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:51:19
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the...
CVE-2022-24885
- EPSS 0.09%
- Veröffentlicht 27.04.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:51:19
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. Version 3.19.1 contains a fix ...
CVE-2021-41233
- EPSS 0.27%
- Veröffentlicht 10.03.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:25:50
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names o...
CVE-2022-24741
- EPSS 0.76%
- Veröffentlicht 09.03.2022 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:50:59
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is re...
CVE-2021-41241
- EPSS 0.23%
- Veröffentlicht 08.03.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:51
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for exa...
CVE-2021-41239
- EPSS 0.37%
- Veröffentlicht 08.03.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:51
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the insta...
CVE-2021-41166
- EPSS 0.23%
- Veröffentlicht 26.01.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:39
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions prior to 3.17.1 may lead to sensitive information disclosure. An unauthorized app that does not have the otherwise required `MANA...
CVE-2021-43863
- EPSS 0.25%
- Veröffentlicht 25.01.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:58
The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCac...
CVE-2021-43608
- EPSS 1.35%
- Veröffentlicht 09.12.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:29:30
Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped use...