
CVE-2015-4716 – Debian Security Advisory 3373-1
https://notcve.org/view.php?id=CVE-2015-4716
19 Oct 2015 — Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors. Vulnerabilidad de salto de directorio en el componente routing en ownCloud Server en versiones anteriores a 7.0.6 y 8.0.x en versiones anteriores a 8.0.4, cuando se ejecuta en Windows, permite a atacantes remotos reinstalar la aplicación o ejecutar código arbitrario a... • http://www.debian.org/security/2015/dsa-3373 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2015-4717 – Debian Security Advisory 3373-1
https://notcve.org/view.php?id=CVE-2015-4717
19 Oct 2015 — The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names. El componente de saneo de nombre de archivo en ownCloud Server en versiones anteriores a 6.0.8, 7.0.x en versiones anteriores a 7.0.6 y 8.0.x en versiones anteriores a 8.0.4 no maneja correctamente la... • http://www.debian.org/security/2015/dsa-3373 • CWE-399: Resource Management Errors •

CVE-2015-4718 – Debian Security Advisory 3373-1
https://notcve.org/view.php?id=CVE-2015-4718
19 Oct 2015 — The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file. El controlador de almacenamiento SMB externo en ownCloud Server en versiones anteriores a 6.0.8, 7.0.x en versiones anteriores a 7.0.6 y 8.0.x en versiones anteriores a 8.0.4 permite a usuarios remotos autenticados ejecutar comandos SMB arbitrarios a través de un carácter ; (punto y coma) en un... • http://www.debian.org/security/2015/dsa-3373 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2015-4456 – Debian Security Advisory 3363-1
https://notcve.org/view.php?id=CVE-2015-4456
21 Sep 2015 — ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by leveraging a self-signed certificate and a connection to a server using its own self-signed certificate. ownCloud Desktop Client en versiones anteriores a 1.8.2 no llama a QNetworkReply::ignoreSslErrors con la lista de errores a ignorar, lo que permite a atacante... • http://www.debian.org/security/2015/dsa-3363 •

CVE-2015-3011 – Debian Security Advisory 3244-1
https://notcve.org/view.php?id=CVE-2015-3011
04 May 2015 — Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact. Múltiples vulnerabilidades de XSS en la aplicación de contactos en ownCloud Server Community Edition anterior a 5.0.19, 6.x anterior a 6.0.7, y 7.x anterior a 7.0.5 permiten a usuarios remotos autenticados inyectar secuencias de comandos web arbi... • http://www.debian.org/security/2015/dsa-3244 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-3012 – Debian Security Advisory 3244-1
https://notcve.org/view.php?id=CVE-2015-3012
04 May 2015 — Multiple cross-site scripting (XSS) vulnerabilities in WebODF before 0.5.5, as used in ownCloud, allow remote attackers to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI. Múltiples vulnerabilidades de XSS en WebODF anterior a 0.5.5, utilizado en ownCloud, permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de una URI (1) de estilos o (2) de nombres de fuentes o (3) de javascript o (4) de datos. Multiple vulnerab... • http://www.debian.org/security/2015/dsa-3244 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-3013 – Debian Security Advisory 3244-1
https://notcve.org/view.php?id=CVE-2015-3013
04 May 2015 — ownCloud Server before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding, as demonstrated by uploading a .htaccess file. ownCloud Server anterior a 5.0.19, 6.x anterior a 6.0.7, y 7.x anterior a 7.0.5 permite a usuarios remotos autenticados evadir la lista negra de ficheros y subir ficheros arbitrarios a través de una ruta de ficheros con la codificación UTF-8, tal y como fue demostrado... • http://www.debian.org/security/2015/dsa-3244 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •

CVE-2014-9044
https://notcve.org/view.php?id=CVE-2014-9044
04 Feb 2015 — Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatenated file, which allows remote attackers to obtain sensitive information via a brute force attack. Asset Pipeline en ownCloud 7.x anterior a 7.0.3 utiliza un hash de MD5 de las rutas de ficheros absolutas de los ficheros originales de CSS y JS como el nombre del fichero concatenado, lo que permite a atacantes remotos obtener información sensible a través de un a... • https://owncloud.org/security/advisory/?id=oc-sa-2014-021 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-9046
https://notcve.org/view.php?id=CVE-2014-9046
04 Feb 2015 — The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol. La función OC_Util::getUrlContent en ownCloud Server anterior a 5.0.18, 6.x anterior a 6.0.6, y 7.x anterior a 7.0.3 permite a atacantes remotos leer ficheros arbitrarios a través de un protocolo file://. • https://owncloud.org/security/advisory/?id=oc-sa-2014-023 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-9047
https://notcve.org/view.php?id=CVE-2014-9047
04 Feb 2015 — Multiple unspecified vulnerabilities in the preview system in ownCloud 6.x before 6.0.6 and 7.x before 7.0.3 allow remote attackers to read arbitrary files via unknown vectors. Múltiples vulnerabilidades no especificadas en el sistema de previsualización en ownCloud 6.x anterior a 6.0.6 y 7.x anterior a 7.0.3 permite a atacantes remotos leer ficheros arbitrarios a través de vectores desconocidos. • https://owncloud.org/security/advisory/?id=oc-sa-2014-026 •