Client
by OwnCloud
Source repositories
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25338 | Med | 0.44 | 6.8 | 0.00 | Apr 7, 2022 | ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. | ||
| CVE-2023-23948 | Med | 0.40 | 6.2 | 0.00 | Feb 13, 2023 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and… | ||
| CVE-2022-25339 | Med | 0.36 | 5.5 | 0.00 | Apr 7, 2022 | ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. | ||
| CVE-2023-24804 | Med | 0.33 | 5.0 | 0.01 | Feb 13, 2023 | The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the… | ||
| CVE-2020-36250 | Med | 0.33 | 6.1 | 0.00 | Feb 19, 2021 | In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past. | ||
| CVE-2020-36248 | Low | 0.18 | 3.9 | 0.00 | Feb 19, 2021 | The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive. | ||
| CVE-2015-5955 | 0.00 | — | 0.01 | Oct 29, 2015 | ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers. | |||
| CVE-2015-7298 | 0.00 | — | 0.01 | Oct 26, 2015 | ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server… |
- risk 0.44cvss 6.8epss 0.00
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
- risk 0.40cvss 6.2epss 0.00
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and…
- risk 0.36cvss 5.5epss 0.00
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
- risk 0.33cvss 5.0epss 0.01
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to information disclosure when uploading the…
- risk 0.33cvss 6.1epss 0.00
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.
- risk 0.18cvss 3.9epss 0.00
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
- CVE-2015-5955Oct 29, 2015risk 0.00cvss —epss 0.01
ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers.
- CVE-2015-7298Oct 26, 2015risk 0.00cvss —epss 0.01
ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server…