Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-31988

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to add the Carriage Return and Line Feed (CRLF) control characters and include arbitrary SMTP headers in the generated test email.
Attacker Value
Unknown

CVE-2021-31987

Disclosure Date: October 05, 2021 (last updated February 23, 2025)
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
Attacker Value
Unknown

CVE-2021-28812

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.
Attacker Value
Unknown

CVE-2020-16220

Disclosure Date: September 11, 2020 (last updated February 22, 2025)
In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input complies with the syntax, causing the certificate enrollment service to crash. It does not impact monitoring but prevents new devices from enrolling.