Vulnerabilities (CVE)

Filtered by vendor Nextcloud Subscribe
Filtered by product End-to-end Encryption
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-35173 1 Nextcloud 1 End-to-end Encryption 2023-12-10 N/A 6.5 MEDIUM
Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end encryption app is upgraded to version 1.12.4 that contains the fix.
CVE-2021-22906 1 Nextcloud 1 End-to-end Encryption 2023-12-10 4.0 MEDIUM 6.5 MEDIUM
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users.