Debian Owncloud-Client vulnerabilities
3 known vulnerabilities affecting debian/owncloud-client.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1LOW2
Vulnerabilities
Page 1 of 1
CVE-2021-44537HIGHCVSS 7.8fixed in owncloud-client 2.11.0.8354+dfsg-1 (bookworm)2021
CVE-2021-44537 [HIGH] CVE-2021-44537: owncloud-client - ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into...
ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
Scope: local
bookworm: resolved (fixed in 2.11.0.8354+dfsg-1)
forky: resolved (fixed in 2.11.0.8354+dfsg-1)
sid: resolved (fixed in 2.11.0.8354+dfsg-1)
trixie: resolved (fixed in 2.11.0.8354+dfsg-1)
debian
CVE-2015-4456LOWCVSS 2.6fixed in owncloud-client 1.8.4+dfsg-1 (bookworm)2015
CVE-2015-4456 [LOW] CVE-2015-4456: owncloud-client - ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslError...
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.
Scope: lo
debian
CVE-2015-7298LOWCVSS 2.6fixed in owncloud-client 2.0.0+dfsg-1 (bookworm)2015
CVE-2015-7298 [LOW] CVE-2015-7298: owncloud-client - ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3....
ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate. NOTE: this vulnerability exists because of a partial
debian