VYPR

Server

by Nextcloud

Source repositories

CVEs (195)

  • CVE-2023-28844MedMar 31, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users…

  • CVE-2023-28835LowMar 30, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions the generated fallback password when creating a share was using a weak complexity random number generator, so when the sharer did not change it the password could be guessable to an attacker…

  • CVE-2023-28833LowMar 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Administrators may have access…

  • CVE-2023-28644MedMar 30, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the…

  • CVE-2023-28643MedMar 30, 2023
    risk 0.00cvss 5.5epss 0.01

    Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended…

  • CVE-2023-25817LowMar 27, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has been addressed andit is…

  • CVE-2023-25818MedMar 27, 2023
    risk 0.00cvss 5.3epss 0.01

    Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to reset the password of another user and then brute force the 62^21 combinations for the password reset token. As of commit `704eb3aa` password reset attempts are…

  • CVE-2023-25820MedMar 22, 2023
    risk 0.00cvss 4.2epss 0.00

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and versions 24.0.x prior to 24.0.10 as…

  • CVE-2023-25821MedFeb 25, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are also given. This issue is…

  • CVE-2023-25816MedFeb 25, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in…

  • CVE-2023-25579MedFeb 22, 2023
    risk 0.00cvss 6.0epss 0.01

    Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFolder()` items, which may allow to…

  • CVE-2023-25162MedFeb 13, 2023
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to 24.0.8 and 23.0.12 and Nextcloud Enterprise server prior to 24.0.8 and 23.0.12 are vulnerable to server-side request forgery (SSRF). Attackers can leverage…

  • CVE-2023-25161LowFeb 13, 2023
    risk 0.00cvss 3.7epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 25.0.1 24.0.8, and 23.0.12 missing rate limiting on password reset functionality. This could result in service…

  • CVE-2023-25159LowFeb 13, 2023
    risk 0.00cvss 2.3epss 0.00

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x…

  • CVE-2022-41970LowDec 1, 2022
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.…

  • CVE-2022-41969LowDec 1, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no password length limit when creating a user as an administrator. An administrator can cause a limited DoS attack against their own server. Versions 23.0.11,…

  • CVE-2022-41968LowDec 1, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths are not validated before writing to a database. As a result, an attacker can send unnecessary amounts of data against the database. Version 23.0.10 and 24.0.5…

  • CVE-2022-39346LowNov 25, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud…

  • CVE-2022-41882MedNov 11, 2022
    risk 0.00cvss 6.6epss 0.00

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. In version 3.6.0, if a user received a malicious file share and has it synced locally or the virtual filesystem enabled and clicked a nc://open/ link it will open the default…

  • CVE-2022-39364MedOct 27, 2022
    risk 0.00cvss 4.0epss 0.00

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain…

Page 8 of 10