owncloud

168 tracked vulnerabilities.

CVE-2014-2057
owncloud < 6.0.1 - Cross-Site Scripting
Mar 24, 2014
EPSS 0.00
CVE-2014-2049
owncloud_server < 5.0.15 and 6.x < 6.0.2 - Unauthenticated File Access via Flash Cross Domain Policy
Mar 14, 2014
EPSS 0.00
CVE-2014-2047
owncloud < 6.0.2 - Session Fixation via GET Request
Mar 14, 2014
EPSS 0.00
CVE-2013-0202 MEDIUM
owncloud_server 4.0.0-4.0.10 - Cross-Site Scripting via Sharing Action Parameter
Dec 17, 2019
CVSS 6.1
EPSS 0.00
CVE-2013-0203 MEDIUM
owncloud < 4.0.10 and 4.5.0-4.5.5 - Cross-Site Scripting via Calendar Event or Bookmark URL Parameters
Nov 22, 2019
CVSS 5.4
EPSS 0.00
CVE-2013-0304
owncloud < 4.5.7 - Authenticated Arbitrary Calendar Read via calid Parameter
Jun 05, 2014
EPSS 0.00
CVE-2013-0302
ownCloud Server <4.0.12 - Info Disclosure
Jun 05, 2014
EPSS 0.00
CVE-2013-1941
ownCloud Server < 4.0.14, 4.5.x < 4.5.9, 5.0.x < 5.0.4 - Weak PostgreSQL Password Generation via Time-Based Seed
Jun 04, 2014
EPSS 0.00
CVE-2013-0204
owncloud_server 4.5.x - Authenticated PHP Code Execution via Mount Point Settings
Jun 04, 2014
EPSS 0.01
CVE-2013-7344
ownCloud < 4.0.12 and 4.5.x < 4.5.6 - Authenticated Remote Code Execution in core/settings.php
Mar 24, 2014
EPSS 0.01
CVE-2013-0303
ownCloud < 4.0.12 and 4.5.x < 4.5.6 - Authenticated Remote Code Execution
Mar 24, 2014
EPSS 0.17
CVE-2013-0201
ownCloud < 4.0.10 - Cross-Site Scripting via QUERY_STRING, mime, or token Parameter
Mar 18, 2014
EPSS 0.00
CVE-2013-0301
owncloud < 4.0.12 - Cross-Site Request Forgery via Timezone Parameter
Mar 14, 2014
EPSS 0.00
CVE-2013-0300
owncloud_server < 4.5.7 - Cross-Site Request Forgery via Calendar View Parameter
Mar 14, 2014
EPSS 0.00
CVE-2013-0299
ownCloud < 4.0.12 and 4.5.x < 4.5.7 - Cross-Site Request Forgery via Multiple Endpoints
Mar 14, 2014
EPSS 0.00
CVE-2013-2150
owncloud_server < 4.5.12 and 5.x < 5.0.7 - Cross-Site Scripting via Shared Files
Mar 14, 2014
EPSS 0.00
CVE-2013-2149
owncloud < 4.0.16 and 5.0.0-5.0.7 - Authenticated Cross-Site Scripting via Shared Files
Mar 14, 2014
EPSS 0.00
CVE-2013-2089
owncloud < 5.0.6 - Authenticated Remote Code Execution via File Upload
Mar 14, 2014
EPSS 0.00
CVE-2013-2086
owncloud_server - Exposure of Sensitive Information via JavaScript File
Mar 14, 2014
EPSS 0.00
CVE-2013-2085
owncloud < 5.0.6 - Authenticated Path Traversal via Dir Parameter
Mar 14, 2014
EPSS 0.00
CVE-2013-2048
ownCloud < 5.0.6 - Authenticated Arbitrary API Command Execution
Mar 14, 2014
EPSS 0.00
CVE-2013-2047
owncloud < 5.0.6 - Password Autocomplete Exposure in Login Page
Mar 14, 2014
EPSS 0.00
CVE-2013-2044
owncloud < 5.0.6 - Open Redirect via Login Page redirect_url Parameter
Mar 14, 2014
EPSS 0.00
CVE-2013-2043
owncloud < 4.5.11 and 5.x < 5.0.6 - Authenticated Arbitrary Calendar Download via calendar_id Parameter
Mar 14, 2014
EPSS 0.00
CVE-2013-2042
ownCloud < 4.0.15, 4.5.x < 4.5.11, 5.0.x < 5.0.6 - Authenticated Cross-Site Scripting via Bookmark URL Parameter
Mar 14, 2014
EPSS 0.00