NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
85800  CVE-2017-0894  Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.    4.3  Medium  2017-05-27  2017-05-17  View
85799  CVE-2017-0893  Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.    3.5  Low  2017-05-27  2017-05-18  View
85798  CVE-2017-0892  Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.    4.3  Medium  2017-05-27  2017-05-17  View
85797  CVE-2017-0891  Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.    3.5  Low  2017-05-27  2017-05-18  View
85796  CVE-2017-0890  Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.    3.5  Low  2017-05-27  2017-05-17  View

Page 513 of 17672, showing 5 records out of 88360 total, starting on record 2561, ending on 2565

Actions