Vulnerabilities > Owncloud > Owncloud > 5.0.9

DATE CVE VULNERABILITY TITLE RISK
2014-06-04 CVE-2014-2055 XML External Entity Injection vulnerability in SabreDAV
SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
network
low complexity
fruux owncloud
7.5
2014-06-04 CVE-2014-2054 XML External Entity Information Disclosure vulnerability in PHPExcel
PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
network
low complexity
owncloud phpexcel-project
7.5
2014-06-04 CVE-2014-2053 XML External Entity Injection vulnerability in ownCloud
getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.
network
low complexity
getid3 owncloud
7.5
2014-03-24 CVE-2014-2585 Improper Input Validation vulnerability in Owncloud
ownCloud before 5.0.15 and 6.x before 6.0.2, when the file_external app is enabled, allows remote authenticated users to mount the local filesystem in the user's ownCloud via the mount configuration.
network
owncloud CWE-20
4.9
2014-03-24 CVE-2014-2057 Cross-Site Scripting vulnerability in Owncloud
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 6.0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
owncloud CWE-79
4.3
2014-03-14 CVE-2014-2049 Permissions, Privileges, and Access Controls vulnerability in Owncloud
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
network
low complexity
owncloud CWE-264
5.0
2014-03-14 CVE-2014-2047 Improper Authentication vulnerability in Owncloud
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.
network
owncloud CWE-287
6.8
2013-12-24 CVE-2013-6403 Permissions, Privileges, and Access Controls vulnerability in Owncloud
The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.
network
owncloud CWE-264
6.8