Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud 7.0.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2015-4717
The filename sanitization component in ownCloud Server prior to 6.0.8, 7.0.x prior to 7.0.6, and 8.0.x prior to 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote malicious users to cause a denial of service (infinite loop and log file co...
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.0
NA
CVE-2015-4718
The external SMB storage driver in ownCloud Server prior to 6.0.8, 7.0.x prior to 7.0.6, and 8.0.x prior to 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.0
NA
CVE-2015-5954
The virtual filesystem in ownCloud Server prior to 6.0.9, 7.0.x prior to 7.0.7, and 8.0.x prior to 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via ...
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud 8.0.4
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.6
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.0
Owncloud Owncloud
NA
CVE-2015-6670
ownCloud Server prior to 7.0.8, 8.0.x prior to 8.0.6, and 8.1.x prior to 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.
Owncloud Owncloud 8.0.5
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud 8.0.4
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.6
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.1.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 7.0.7
Owncloud Owncloud 8.0.0
NA
CVE-2015-7699
The files_external app in ownCloud Server prior to 7.0.9, 8.0.x prior to 8.0.7, and 8.1.x prior to 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."
Owncloud Owncloud 8.0.5
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud 8.0.4
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.6
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.1.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 7.0.7
Owncloud Owncloud 8.0.0
NA
CVE-2015-6500
Directory traversal vulnerability in ownCloud Server prior to 8.0.6 and 8.1.x prior to 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/...
Owncloud Owncloud 8.0.5
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud 8.0.4
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 7.0.6
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.1.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 7.0.7
Owncloud Owncloud 8.0.0
NA
CVE-2014-9047
Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x prior to 6.0.6 and 7.x prior to 7.0.3 allow remote malicious users to read arbitrary files via unknown vectors.
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.2
Owncloud Owncloud 7.0.1
Owncloud Owncloud 6.0.5
Owncloud Owncloud 6.0.2
Owncloud Owncloud 7.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.16
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.1
Owncloud Owncloud 6.0.4
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.13
Owncloud Owncloud 7.0.0
Owncloud Owncloud 5.0.8
Owncloud Owncloud
Owncloud Owncloud 6.0.3
NA
CVE-2014-9046
The OC_Util::getUrlContent function in ownCloud Server prior to 5.0.18, 6.x prior to 6.0.6, and 7.x prior to 7.0.3 allows remote malicious users to read arbitrary files via a file:// protocol.
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.2
Owncloud Owncloud 7.0.1
Owncloud Owncloud 6.0.5
Owncloud Owncloud 6.0.2
Owncloud Owncloud 7.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.16
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.1
Owncloud Owncloud 6.0.4
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.13
Owncloud Owncloud 7.0.0
Owncloud Owncloud 5.0.8
Owncloud Owncloud
Owncloud Owncloud 6.0.3
NA
CVE-2014-9048
The documents application in ownCloud Server 6.x prior to 6.0.6 and 7.x prior to 7.0.3 allows remote malicious users to bypass the password-protection for shared files via the API.
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.2
Owncloud Owncloud 7.0.1
Owncloud Owncloud 6.0.5
Owncloud Owncloud 6.0.2
Owncloud Owncloud 7.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.16
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.1
Owncloud Owncloud 6.0.4
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.13
Owncloud Owncloud 7.0.0
Owncloud Owncloud 5.0.8
Owncloud Owncloud
Owncloud Owncloud 6.0.3
NA
CVE-2014-9041
The import functionality in the bookmarks application in ownCloud server prior to 5.0.18, 6.x prior to 6.0.6, and 7.x prior to 7.0.3 does not validate CSRF tokens, which allow remote malicious users to conduct CSRF attacks.
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.2
Owncloud Owncloud 7.0.1
Owncloud Owncloud 6.0.5
Owncloud Owncloud 6.0.2
Owncloud Owncloud 7.0.2
Owncloud Owncloud 5.0.3
Owncloud Owncloud 5.0.9
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.16
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.1
Owncloud Owncloud 6.0.4
Owncloud Owncloud 5.0.12
Owncloud Owncloud 5.0.4
Owncloud Owncloud 5.0.13
Owncloud Owncloud 7.0.0
Owncloud Owncloud 5.0.8
Owncloud Owncloud
Owncloud Owncloud 6.0.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »