Total
52 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-8183 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call. | |||||
CVE-2020-8236 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.6 MEDIUM | 6.8 MEDIUM |
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it. | |||||
CVE-2020-8259 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 5.5 MEDIUM | 8.1 HIGH |
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys. | |||||
CVE-2021-22877 | 2 Fedoraproject, Nextcloud | 2 Fedora, Nextcloud | 2024-02-04 | 5.5 MEDIUM | 6.5 MEDIUM |
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. | |||||
CVE-2020-8225 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 5.0 MEDIUM | 7.5 HIGH |
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials. | |||||
CVE-2020-8152 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 2.1 LOW | 4.4 MEDIUM |
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on. | |||||
CVE-2020-8293 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.0 MEDIUM | 6.5 MEDIUM |
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules. | |||||
CVE-2020-8173 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 3.5 LOW | 2.2 LOW |
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended. | |||||
CVE-2020-8230 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 2.1 LOW | 5.5 MEDIUM |
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory. | |||||
CVE-2020-8229 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.9 MEDIUM | 5.5 MEDIUM |
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system. | |||||
CVE-2020-8140 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.6 MEDIUM | 6.7 MEDIUM |
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment. | |||||
CVE-2020-8189 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt. | |||||
CVE-2020-8224 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.6 MEDIUM | 7.8 HIGH |
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. | |||||
CVE-2020-8227 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 7.1 HIGH | 6.8 MEDIUM |
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory. | |||||
CVE-2019-15611 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.0 MEDIUM | 4.9 MEDIUM |
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or registering for push notifications. | |||||
CVE-2019-15622 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 2.1 LOW | 2.4 LOW |
Not strictly enough sanitization in the Nextcloud Android app 3.6.0 allowed an attacker to get content information from protected tables when using custom queries. | |||||
CVE-2019-15615 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 3.6 LOW | 6.1 MEDIUM |
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. | |||||
CVE-2019-15614 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 3.5 LOW | 5.4 MEDIUM |
Missing sanitization in the iOS App 2.24.4 causes an XSS when opening malicious HTML files. | |||||
CVE-2019-5453 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 3.6 LOW | 6.1 MEDIUM |
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | |||||
CVE-2019-5455 | 1 Nextcloud | 1 Nextcloud | 2024-02-04 | 4.6 MEDIUM | 6.8 MEDIUM |
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. |