Owncloud Client

Vendor:

First CVE: Oct 29, 2015 · Active for 10 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Owncloud Client over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 29, 2015
10 years ago
Most Recent CVE
Feb 13, 2023
1,257 days ago

CVE Severity & Scoring

Owncloud Client7 CVEs
All CVEs352,231 CVEs
Medium
Attack Vector
Local3 (42.9%)
Network0 (0.0%)
Unknown1 (14.3%)
Physical3 (42.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High0 (0.0%)
Unknown1 (14.3%)
User Interaction
None5 (71.4%)
Unknown1 (14.3%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None4 (57.1%)
Unknown1 (14.3%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers.
Apr 7, 20226.823NONO
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileConte
Feb 13, 20235.520NONO
ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers.
Apr 7, 20225.520NONO
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is v
Feb 13, 20234.418NONO
In the ownCloud application before 2.15 for Android, the lock protection mechanism can be bypassed by moving the system date/time into the past.
Feb 19, 20214.617NONO
The ownCloud application before 2.15 for Android allows attackers to use adb to include a PIN preferences value in a backup archive, and consequently bypass the PIN lock feature by
Feb 19, 20214.616NONO
ownCloud iOS app before 3.4.4 does not properly switch state between multiple instances, which might allow remote instance administrators to obtain sensitive credential and cookie
Oct 29, 20155.015NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Owncloud Client

Top CWEs

Versions

No cataloged versions.