Логотип exploitDog
product: "nextcloud_server"
Консоль
Логотип exploitDog

exploitDog

product: "nextcloud_server"
Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3132202520262027

Недавние уязвимости Nextcloud Server

Количество 440

nvd логотип

CVE-2018-3762

больше 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-3762

больше 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-3761

больше 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-3761

больше 7 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authent ...

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:1040-1

почти 8 лет назад

Security update for nextcloud

EPSS: Низкий
nvd логотип

CVE-2017-0936

почти 8 лет назад

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2017-0936

почти 8 лет назад

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorizatio ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2017-0895

больше 8 лет назад

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2017-0895

больше 8 лет назад

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2017-0894

больше 8 лет назад

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-3762

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-3762

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks ...

CVSS3: 4.3
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-3761

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.

CVSS3: 8.1
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-3761

Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authent ...

CVSS3: 8.1
1%
Низкий
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:1040-1

Security update for nextcloud

0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0936

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.

CVSS3: 5.7
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2017-0936

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorizatio ...

CVSS3: 5.7
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2017-0895

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2017-0895

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure ...

CVSS3: 3.5
0%
Низкий
больше 8 лет назад
nvd логотип
CVE-2017-0894

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу


Поделиться