Vulnerabilities > Nextcloud > Nextcloud Server > Low

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2020-8173 Missing Encryption of Sensitive Data vulnerability in Nextcloud Server
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
network
high complexity
nextcloud CWE-311
2.2
2018-10-30 CVE-2018-16463 Session Fixation vulnerability in Nextcloud Server
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
network
high complexity
nextcloud CWE-384
3.1
2017-05-08 CVE-2017-0892 Session Fixation vulnerability in Nextcloud Server
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
network
low complexity
nextcloud CWE-384
3.5
2017-05-08 CVE-2017-0895 Information Exposure vulnerability in Nextcloud Server
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users.
network
low complexity
nextcloud CWE-200
3.5