V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2014-2055
DEB
High

SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, c…

CVSS
7.5
High
EPSS
0.02
p80
Published
2014-01-01
Updated
2014-01-01
Description

SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

Affected products
Sabredav ≤ 1.7.10SabredavOwncloud_server
CVSS vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Timeline
2014-01-01
Published
2014-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: P
Partial
Availability Impact
A: P
Partial
Exploit indicators
EPSS
0.022 · p80
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
owncloudTracked
owncloudTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
php-sabredavTracked
owncloud_server*Tracked
owncloud_server*Tracked
sabredav*Tracked
sabredav*Tracked
Source databases
DEB
CVE
UBU