Количество 409
Количество 409
CVE-2017-0936
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorizatio ...

CVE-2017-0895
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
CVE-2017-0895
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure ...

CVE-2017-0894
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
CVE-2017-0894
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid sh ...

CVE-2017-0893
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.
CVE-2017-0893
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vu ...

CVE-2017-0892
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
CVE-2017-0892
Nextcloud Server before 11.0.3 is vulnerable to an improper session ha ...

CVE-2017-0891
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.
CVE-2017-0891
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to ...

CVE-2017-0890
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.
CVE-2017-0890
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping ...

CVE-2017-0887
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.
CVE-2017-0887
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the ...

CVE-2017-0886
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.
CVE-2017-0886
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Ser ...

CVE-2017-0885
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
CVE-2017-0885
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message ...

CVE-2017-0884
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
CVE-2017-0936 Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorizatio ... | CVSS3: 5.7 | 0% Низкий | около 7 лет назад | |
![]() | CVE-2017-0895 Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed. | CVSS3: 3.5 | 0% Низкий | около 8 лет назад |
CVE-2017-0895 Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure ... | CVSS3: 3.5 | 0% Низкий | около 8 лет назад | |
![]() | CVE-2017-0894 Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token. | CVSS3: 4.3 | 1% Низкий | около 8 лет назад |
CVE-2017-0894 Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid sh ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
![]() | CVE-2017-0893 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers. | CVSS3: 5.4 | 0% Низкий | около 8 лет назад |
CVE-2017-0893 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vu ... | CVSS3: 5.4 | 0% Низкий | около 8 лет назад | |
![]() | CVE-2017-0892 Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file. | CVSS3: 3.5 | 1% Низкий | около 8 лет назад |
CVE-2017-0892 Nextcloud Server before 11.0.3 is vulnerable to an improper session ha ... | CVSS3: 3.5 | 1% Низкий | около 8 лет назад | |
![]() | CVE-2017-0891 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components. | CVSS3: 5.4 | 0% Низкий | около 8 лет назад |
CVE-2017-0891 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to ... | CVSS3: 5.4 | 0% Низкий | около 8 лет назад | |
![]() | CVE-2017-0890 Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue. | CVSS3: 5.4 | 1% Низкий | около 8 лет назад |
CVE-2017-0890 Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping ... | CVSS3: 5.4 | 1% Низкий | около 8 лет назад | |
![]() | CVE-2017-0887 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator. | CVSS3: 4.3 | 0% Низкий | около 8 лет назад |
CVE-2017-0887 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the ... | CVSS3: 4.3 | 0% Низкий | около 8 лет назад | |
![]() | CVE-2017-0886 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service. | CVSS3: 6.5 | 1% Низкий | около 8 лет назад |
CVE-2017-0886 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Ser ... | CVSS3: 6.5 | 1% Низкий | около 8 лет назад | |
![]() | CVE-2017-0885 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages. | CVSS3: 4.3 | 1% Низкий | около 8 лет назад |
CVE-2017-0885 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
![]() | CVE-2017-0884 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for. | CVSS3: 4.3 | 0% Низкий | около 8 лет назад |
Уязвимостей на страницу