VYPR

Nextcloud

by Nextcloud

Source repositories

CVEs (144)

  • CVE-2023-30540LowApr 17, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in…

  • CVE-2023-28999MedApr 4, 2023
    risk 0.00cvss 6.9epss 0.01

    Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can…

  • CVE-2023-28845LowMar 31, 2023
    risk 0.00cvss 3.5epss 0.00

    Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation,…

  • CVE-2023-28647MedMar 30, 2023
    risk 0.00cvss 4.4epss 0.00

    Nextcloud iOS is an ios application used to interface with the nextcloud home cloud ecosystem. In versions prior to 4.7.0 when an attacker has physical access to an unlocked device, they may enable the integration into the iOS Files app and bypass the Nextcloud pin/password…

  • CVE-2023-28646MedMar 30, 2023
    risk 0.00cvss 4.4epss 0.00

    Nextcloud android is an android app for interfacing with the nextcloud home server ecosystem. In versions from 3.7.0 and before 3.24.1 an attacker that has access to the unlocked physical device can bypass the Nextcloud Android Pin/passcode protection via a thirdparty app. This…

  • CVE-2023-26041LowFeb 27, 2023
    risk 0.00cvss 2.6epss 0.01

    Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code. It is recommended that the Nextcloud Talk…

  • CVE-2023-25821MedFeb 25, 2023
    risk 0.00cvss 5.7epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are also given. This issue is…

  • CVE-2023-25816MedFeb 25, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in…

  • CVE-2023-22470LowJan 14, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A database error can be generated potentially causing a DoS when performed multiple times. There are currently no known workarounds. It is…

  • CVE-2023-22473LowJan 9, 2023
    risk 0.00cvss 2.1epss 0.01

    Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There…

  • CVE-2022-39334LowNov 25, 2022
    risk 0.00cvss 3.9epss 0.00

    Nextcloud also ships a CLI utility called nextcloudcmd which is sometimes used for automated scripting and headless servers. Versions of nextcloudcmd prior to 3.6.1 would incorrectly trust invalid TLS certificates, which may enable a Man-in-the-middle attack that exposes…

  • CVE-2022-39212MedSep 17, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is…

  • CVE-2022-39210LowSep 17, 2022
    risk 0.00cvss 3.2epss 0.00

    Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud Android app files are not properly protected. As a result access to internal files of the from within the Nextcloud Android app is possible. This may lead to…

  • CVE-2022-31119LowAug 4, 2022
    risk 0.00cvss 3.1epss 0.01

    Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail would log user passwords to disk in the event of a misconfiguration. Should an attacker gain access to the logs complete access to affected accounts would be…

  • CVE-2022-31131MedJul 6, 2022
    risk 0.00cvss 5.4epss 0.01

    Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were found to be missing user account ownership checks when performing tasks related to mail attachments. Attachments may have been exposed to incorrect system users.…

  • CVE-2022-29160LowMay 20, 2022
    risk 0.00cvss 2.8epss 0.00

    Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.0, sensitive tokens, images, and user related details exist after deletion of a user account. This could result in misuse of the former account holder's information.…

  • CVE-2022-24890LowMay 17, 2022
    risk 0.00cvss 2.4epss 0.01

    Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5…

  • CVE-2022-24887MedApr 27, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versions 11.3.4, 12.2.2, and 13.0.0, when sharing a Deck card in conversation, the metaData can be manipulated so users can be tricked into opening arbitrary URLs.…

  • CVE-2022-24886LowApr 27, 2022
    risk 0.00cvss 2.2epss 0.00

    Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Contacts permission itself.…

  • CVE-2022-24885LowApr 27, 2022
    risk 0.00cvss 2.0epss 0.00

    Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1, users can bypass a lock on the Nextcloud app on an Android device by repeatedly reopening the app. Version 3.19.1 contains a fix for the problem. There are…

Page 6 of 8