Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
owncloud owncloud vulnerabilities and exploits
(subscribe to this query)
9
CVSSv2
CVE-2015-7698
icewind1991 SMB prior to 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.
Owncloud Smb
Owncloud Owncloud
10
CVSSv2
CVE-2015-4716
Directory traversal vulnerability in the routing component in ownCloud Server prior to 7.0.6 and 8.0.x prior to 8.0.4, when running on Windows, allows remote malicious users to reinstall the application or execute arbitrary code via unspecified vectors.
Owncloud Owncloud
Owncloud Owncloud 8.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.3
Microsoft Windows
7.8
CVSSv2
CVE-2015-4717
The filename sanitization component in ownCloud Server prior to 6.0.8, 7.0.x prior to 7.0.6, and 8.0.x prior to 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote malicious users to cause a denial of service (infinite loop and log file co...
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.5
Owncloud Owncloud 8.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.3
Owncloud Owncloud 7.0.2
Owncloud Owncloud 7.0.4
Owncloud Owncloud
Owncloud Owncloud 7.0.0
9
CVSSv2
CVE-2015-4718
The external SMB storage driver in ownCloud Server prior to 6.0.8, 7.0.x prior to 7.0.6, and 8.0.x prior to 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.
Owncloud Owncloud
Owncloud Owncloud 7.0.1
Owncloud Owncloud 8.0.0
Owncloud Owncloud 8.0.3
Owncloud Owncloud 7.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 7.0.2
Owncloud Owncloud 7.0.3
Owncloud Owncloud 7.0.4
Owncloud Owncloud 7.0.5
3.5
CVSSv2
CVE-2015-5953
Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server prior to 7.0.5 and 8.0.x prior to 8.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a " (double quote) character in a filename in a shared folder.
Owncloud Owncloud
Owncloud Owncloud 8.0.0
Owncloud Owncloud 8.0.2
Owncloud Owncloud 8.0.3
3.5
CVSSv2
CVE-2015-3011
Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition prior to 5.0.19, 6.x prior to 6.0.7, and 7.x prior to 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact.
Owncloud Owncloud
Debian Debian Linux 7.0
4.3
CVSSv2
CVE-2015-3012
Multiple cross-site scripting (XSS) vulnerabilities in WebODF prior to 0.5.5, as used in ownCloud, allow remote malicious users to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.
Debian Debian Linux 7.0
Kogmbh Webodf
6
CVSSv2
CVE-2015-3013
ownCloud Server prior to 5.0.19, 6.x prior to 6.0.7, and 7.x prior to 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file.
Owncloud Owncloud
3.5
CVSSv2
CVE-2014-9042
Cross-site scripting (XSS) vulnerability in the import functionality in the bookmarks application in ownCloud prior to 5.0.18, 6.x prior to 6.0.6, and 7.x prior to 7.0.3 allows remote authenticated users to inject arbitrary web script or HTML by importing a link with an unspecifi...
Owncloud Owncloud 5.0.0
Owncloud Owncloud 5.0.5
Owncloud Owncloud 5.0.6
Owncloud Owncloud 5.0.7
Owncloud Owncloud 5.0.8
Owncloud Owncloud 5.0.14
Owncloud Owncloud 5.0.15
Owncloud Owncloud 5.0.16
Owncloud Owncloud 6.0.3
Owncloud Owncloud 6.0.4
Owncloud Owncloud 6.0.5
Owncloud Owncloud 7.0.0
Owncloud Owncloud 5.0.1
Owncloud Owncloud 5.0.11
Owncloud Owncloud 5.0.13
Owncloud Owncloud
Owncloud Owncloud 5.0.3
Owncloud Owncloud 6.0.0
Owncloud Owncloud 6.0.2
Owncloud Owncloud 7.0.1
Owncloud Owncloud 5.0.10
Owncloud Owncloud 5.0.12
5
CVSSv2
CVE-2014-9044
Asset Pipeline in ownCloud 7.x prior to 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote malicious users to obtain sensitive information via a brute force attack.
Owncloud Owncloud 7.0.0
Owncloud Owncloud 7.0.1
Owncloud Owncloud 7.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
3
4
5
6
7
8
9
10
NEXT »