Vulnerabilities > Nextcloud > Desktop > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-22895 Improper Certificate Validation vulnerability in multiple products
Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate verification when using the "Register with a Provider" flow.
network
high complexity
nextcloud debian CWE-295
5.9
2020-08-21 CVE-2020-8227 Path Traversal vulnerability in Nextcloud Desktop
Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory.
network
low complexity
nextcloud CWE-22
6.8
2020-08-21 CVE-2020-8189 Cross-site Scripting vulnerability in Nextcloud Desktop
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
network
low complexity
nextcloud CWE-79
5.4
2020-08-17 CVE-2020-8230 Out-of-bounds Write vulnerability in Nextcloud Desktop
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
local
low complexity
nextcloud CWE-787
5.5
2020-08-10 CVE-2020-8229 Memory Leak vulnerability in Nextcloud Desktop
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
local
low complexity
nextcloud CWE-401
5.5
2020-03-20 CVE-2020-8140 Code Injection vulnerability in Nextcloud Desktop
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
local
low complexity
nextcloud CWE-94
6.7