CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
97701 | CVE-2017-0882 | Candidate | Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC. | Assigned (20161130) | None (candidate not yet proposed) | View | |
97702 | CVE-2017-0883 | Candidate | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a "read" permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for. | Assigned (20161130) | None (candidate not yet proposed) | View | |
97703 | CVE-2017-0884 | Candidate | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for. | Assigned (20161130) | None (candidate not yet proposed) | View | |
97704 | CVE-2017-0885 | Candidate | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages. | Assigned (20161130) | None (candidate not yet proposed) | View | |
97705 | CVE-2017-0886 | Candidate | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service. | Assigned (20161130) | None (candidate not yet proposed) | View |
Page 19541 of 20943, showing 5 records out of 104715 total, starting on record 97701, ending on 97705