Owncloud Desktop Client vulnerabilities

5 known vulnerabilities affecting owncloud/owncloud_desktop_client.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2021-44537HIGHCVSS 7.8fixed in 2.9.22022-01-15
CVE-2021-44537 [HIGH] CWE-74 CVE-2021-44537: ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.
nvd
CVE-2020-28646HIGHCVSS 7.8fixed in 2.72021-02-26
CVE-2020-28646 [HIGH] CWE-427 CVE-2020-28646: ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plug ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
nvd
CVE-2016-7102HIGHCVSS 8.4≤ 2.2.22017-01-23
CVE-2016-7102 [HIGH] CWE-94 CVE-2016-7102: ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privile ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.
nvd
CVE-2015-7298MEDIUMCVSS 5.1≤ 2.0.02015-10-26
CVE-2015-7298 [MEDIUM] CVE-2015-7298: ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNe ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes it easier for remote attackers to conduct man-in-the-middle (MITM) attacks by leveraging a server using a self-signed certificate. NOTE: this vulnerability exists because of a partia
nvd
CVE-2015-4456LOWCVSS 2.6≤ 1.8.12015-10-26
CVE-2015-4456 [LOW] CVE-2015-4456: ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of e ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate.
nvd