CVE-2021-32694
MEDIUMNextcloud Android < 3.15.1 - Denial of Service via Uncaught Exception
Title source: llmDescription
Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the same device is possible to crash the Nextcloud Android Client due to an uncaught exception. The vulnerability is patched in version 3.15.1.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_confirm
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h2gm-m374-99vc
Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/android/pull/7919
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/859136
Scores
CVSS v3
4.1
EPSS
0.0097
EPSS Percentile
57.0%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-248
Status
published
Products (1)
nextcloud/nextcloud
< 3.15.1
Published
Jun 17, 2021
Tracked Since
Feb 18, 2026