Total
28 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-15615 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 3.6 LOW | 6.1 MEDIUM |
A wrong check for the system time in the Android App 3.9.0 causes a bypass of the lock protection when changing the time of the system to the past. | |||||
CVE-2019-5455 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 4.6 MEDIUM | 6.8 MEDIUM |
Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. | |||||
CVE-2019-5454 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 7.5 HIGH | 9.8 CRITICAL |
SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account. | |||||
CVE-2019-5450 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 4.6 MEDIUM | 6.8 MEDIUM |
Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style the directory name in the header bar when using basic HTML. | |||||
CVE-2019-5452 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 2.1 LOW | 2.4 LOW |
Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting the Android content provider although the lock protection was not solved. | |||||
CVE-2019-5453 | 1 Nextcloud | 1 Nextcloud | 2023-12-10 | 3.6 LOW | 6.1 MEDIUM |
Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted for the lock protection and switching to the Nextcloud file provider. | |||||
CVE-2016-9460 | 2 Nextcloud, Owncloud | 2 Nextcloud, Owncloud | 2023-12-10 | 5.0 MEDIUM | 5.3 MEDIUM |
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake directory structure and use this to display an attacker-controlled error message to the user. | |||||
CVE-2017-0888 | 1 Nextcloud | 2 Nextcloud, Nextcloud Server | 2023-12-10 | 4.3 MEDIUM | 4.3 MEDIUM |
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information. |