Back to Database
Status published
Medium
CVE-2014-9046
The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before...
Vulnerability Description
The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-9046
Credits & Attribution
No credits recorded in the NVD database.
More from owncloud
View All →CVE-2025-53831
DrawIO for ownCloud 10 is vulnerable to Stored XSS
High
8.2
CVE-2025-53830
Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
Critical
9.1
CVE-2025-53829
ownCloud 10 is vulnerable to Relative Path Traversal
High
8
CVE-2025-53828
SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)
High
8.5
CVE-2025-53827
ownCloud Core: Updater has an exposed dangerous method or function
Critical
9.1
Affected Vendor
owncloud
View all reports →Affected Software
owncloud, owncloud server
Vulnerable Versions:
0, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.0.16, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 7.0.0, 7.0.1, 7.0.2
Timeline
Official Publish:
February 4th, 2015
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.