VendorsownCloudowncloud_clientall versions
Vulnerabilities

ownCloud Client

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-25338
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
Published 2022-04-07 · Analyzed
6.8EPSS 0.002
CVE-2023-23948
ownCloud Android app vulnerable to SQL Injection
Published 2023-02-13 · Modified
6.2EPSS 0.005
CVE-2020-36250
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.
Published 2021-02-19 · Modified
6.1EPSS 0.003
CVE-2022-25339
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
Published 2022-04-07 · Analyzed
5.5EPSS 0.002
CVE-2015-5955
ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie information by reading authentication headers.
Published 2015-10-29 · Modified
5.0EPSS 0.011
CVE-2023-24804
ownCloud Android app vulnerable to Path Traversal
Published 2023-02-13 · Analyzed
5.0EPSS 0.005
CVE-2020-36248
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by restoring from this archive.
Published 2021-02-19 · Modified
4.6EPSS 0.001