Логотип exploitDog
product: "nextcloud_server"
Консоль
Логотип exploitDog

exploitDog

product: "nextcloud_server"
Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

30312024202520262027

Недавние уязвимости Nextcloud Server

Количество 409

nvd логотип

CVE-2017-0893

около 8 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-0893

около 8 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vu ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-0892

около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2017-0892

около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an improper session ha ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2017-0891

около 8 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-0891

около 8 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-0890

около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2017-0890

около 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2017-0888

около 8 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-0888

около 8 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoof ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2017-0893

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-0893

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vu ...

CVSS3: 5.4
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-0892

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS3: 3.5
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-0892

Nextcloud Server before 11.0.3 is vulnerable to an improper session ha ...

CVSS3: 3.5
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-0891

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-0891

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to ...

CVSS3: 5.4
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-0890

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

CVSS3: 5.4
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-0890

Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping ...

CVSS3: 5.4
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-0888

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.

CVSS3: 4.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-0888

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoof ...

CVSS3: 4.3
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться