CVE-2014-3834: ownCloud
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access the contacts of other users via the address book or (2) rename files via unspecified vectors.
Affected products
- ownCloud ownCloud: up to and including 6.0.2
- ownCloud ownCloud Server: version 6.0.0 only; version 6.0.1 only
Published 2014-06-04. Last modified 2026-06-17.