ownCloud Server (ownCloud Core) 8.0.4 Release Candidate 2

CPE Details

ownCloud Server (ownCloud Core) 8.0.4 Release Candidate 2
8.0.4
2025-03-31
09h54 +00:00
2025-03-31
09h54 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:owncloud:owncloud_server:8.0.4:rc2:*:*:*:*:*:*

Informations

Vendor

owncloud

Product

owncloud_server

Version

8.0.4

Update

rc2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-1498 2016-01-08 20h00 +00:00 Cross-site scripting (XSS) vulnerability in the OCS discovery provider component in ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a URL.
6.1
Medium
CVE-2016-1500 2016-01-08 20h00 +00:00 ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share.
3.1
Low
CVE-2015-7699 2015-10-26 14h00 +00:00 The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."
9
CVE-2015-6500 2015-10-26 13h00 +00:00 Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.
7.5
CVE-2015-6670 2015-10-26 13h00 +00:00 ownCloud Server before 7.0.8, 8.0.x before 8.0.6, and 8.1.x before 8.1.1 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to apps/calendar/export.php.
4
CVE-2015-5954 2015-10-21 16h00 +00:00 The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0.5 does not consider that NULL is a valid getPath return value, which allows remote authenticated users to bypass intended access restrictions and gain access to users files via a sharing link to a file with a deleted parent folder.
4