Vulnerabilities (CVE)

Filtered by vendor Owncloud Subscribe
Filtered by product Files Antivirus
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-33827 1 Owncloud 1 Files Antivirus 2024-02-28 9.0 HIGH 7.2 HIGH
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
CVE-2021-33828 1 Owncloud 1 Files Antivirus 2024-02-28 6.5 MEDIUM 8.8 HIGH
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
CVE-2020-16144 1 Owncloud 1 Files Antivirus 2024-02-28 3.5 LOW 5.7 MEDIUM
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component versions before 0.15.2 for ownCloud.