Vulnerabilities > Nextcloud

DATE CVE VULNERABILITY TITLE RISK
2020-08-17 CVE-2020-8230 Out-of-bounds Write vulnerability in Nextcloud Desktop
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
local
low complexity
nextcloud CWE-787
2.1
2020-08-10 CVE-2020-8229 Memory Leak vulnerability in Nextcloud Desktop
A memory leak in the OCUtil.dll library used by Nextcloud Desktop Client 2.6.4 can lead to a DoS against the host system.
local
low complexity
nextcloud CWE-401
4.9
2020-08-10 CVE-2020-8224 Code Injection vulnerability in Nextcloud Desktop
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
local
low complexity
nextcloud CWE-94
7.8
2020-07-30 CVE-2020-8202 Improper Restriction of Excessive Authentication Attempts vulnerability in Nextcloud Preferred Providers 1.6.0
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
network
low complexity
nextcloud CWE-307
5.0
2020-07-10 CVE-2020-8181 Unrestricted Upload of File with Dangerous Type vulnerability in Nextcloud Contacts
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
network
low complexity
nextcloud CWE-434
4.3
2020-07-02 CVE-2020-8179 Improper Privilege Management vulnerability in Nextcloud Deck
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
network
low complexity
nextcloud CWE-269
4.0
2020-06-08 CVE-2020-8180 Code Injection vulnerability in Nextcloud Talk
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
network
low complexity
nextcloud CWE-94
6.5
2020-05-12 CVE-2020-8156 Improper Certificate Validation vulnerability in multiple products
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
network
high complexity
nextcloud fedoraproject CWE-295
7.0
2020-05-12 CVE-2020-8155 Cross-site Scripting vulnerability in Nextcloud Server
An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.
network
low complexity
nextcloud CWE-79
5.4
2020-05-12 CVE-2020-8154 Authorization Bypass Through User-Controlled Key vulnerability in Nextcloud Server
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
network
low complexity
nextcloud CWE-639
7.7