Vulnerabilities > Owncloud > Owncloud > 9.0.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-09 | CVE-2020-28645 | Improper Input Validation vulnerability in Owncloud Deleting users with certain names caused system files to be deleted. | 5.0 |
2021-02-09 | CVE-2020-28644 | Cross-Site Request Forgery (CSRF) vulnerability in Owncloud The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. | 4.3 |
2021-01-15 | CVE-2020-16255 | Cross-site Scripting vulnerability in Owncloud ownCloud (Core) before 10.5 allows XSS in login page 'forgot password.' | 4.3 |
2017-07-17 | CVE-2017-9340 | Unspecified vulnerability in Owncloud An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2. | 4.0 |
2017-07-17 | CVE-2017-9339 | Unspecified vulnerability in Owncloud A logical error in ownCloud Server before 10.0.2 caused disclosure of valid share tokens for public calendars. | 5.0 |
2017-07-17 | CVE-2017-9338 | Cross-site Scripting vulnerability in Owncloud Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. | 3.5 |
2017-07-17 | CVE-2017-8896 | Cross-site Scripting vulnerability in Owncloud ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2 are vulnerable to XSS on error pages by injecting code in url parameters. | 4.3 |
2017-03-03 | CVE-2017-5867 | Resource Exhaustion vulnerability in Owncloud ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file. | 4.0 |
2017-03-03 | CVE-2017-5866 | Information Exposure vulnerability in Owncloud The autocomplete feature in the E-Mail share dialog in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to obtain sensitive information via unspecified vectors. | 4.0 |
2017-03-03 | CVE-2017-5865 | Information Exposure vulnerability in Owncloud The password reset functionality in ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 sends different error messages depending on whether the username is valid, which allows remote attackers to enumerate user names via a large number of password reset attempts. | 4.3 |