Vulnerabilities > Nextcloud > Desktop > Low

DATE CVE VULNERABILITY TITLE RISK
2020-08-21 CVE-2020-8189 Cross-site Scripting vulnerability in Nextcloud Desktop
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
network
nextcloud CWE-79
3.5
2020-08-17 CVE-2020-8230 Out-of-bounds Write vulnerability in Nextcloud Desktop
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
local
low complexity
nextcloud CWE-787
2.1