Nextcloud

Desktop

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 05.12.2025 17:47:00
  • Zuletzt bearbeitet 09.12.2025 18:58:22

Nextcloud Desktop is the desktop sync client for Nextcloud. Prior to 3.16.5, when trying to manually lock a file inside an end-to-end encrypted directory, the path of the file was sent to the server unencrypted, making it possible for administrators ...

  • EPSS 0.01%
  • Veröffentlicht 16.05.2025 14:13:53
  • Zuletzt bearbeitet 08.09.2025 21:22:39

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then...

  • EPSS 0.47%
  • Veröffentlicht 15.11.2024 18:15:29
  • Zuletzt bearbeitet 28.08.2025 14:21:08

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error but allowed by-passing the signature validation, if a manipulated server sends an empty initial signat...

  • EPSS 0.15%
  • Veröffentlicht 16.09.2024 02:15:01
  • Zuletzt bearbeitet 13.03.2025 18:15:44

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.

  • EPSS 0.13%
  • Veröffentlicht 14.06.2024 16:15:13
  • Zuletzt bearbeitet 21.11.2024 09:24:28

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the...

  • EPSS 0.75%
  • Veröffentlicht 04.04.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 07:56:22

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious serv...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 04.04.2023 13:15:09
  • Zuletzt bearbeitet 21.11.2024 07:56:22

Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-e...

Exploit
  • EPSS 0.68%
  • Veröffentlicht 04.04.2023 13:15:08
  • Zuletzt bearbeitet 21.11.2024 07:56:21

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files...

Exploit
  • EPSS 0.58%
  • Veröffentlicht 04.04.2023 13:15:08
  • Zuletzt bearbeitet 03.11.2025 19:15:41

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users shoul...

  • EPSS 1.11%
  • Veröffentlicht 06.02.2023 21:15:09
  • Zuletzt bearbeitet 21.11.2024 07:47:09

The Nextcloud Desktop Client is a tool to synchronize files from a Nextcloud Server with your computer. Versions prior to 3.6.3 are missing sanitisation on qml labels which are used for basic HTML elements such as `strong`, `em` and `head` lines in t...