Show filters
88 Total Results
Displaying 11-20 of 88
Sort by:
Attacker Value
Unknown
CVE-2022-27626
Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding concurrent execution using shared resource with improper synchronization ('Race Condition') is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
0
Attacker Value
Unknown
CVE-2022-3576
Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding out-of-bounds read is found in the session processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to obtain sensitive information via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
0
Attacker Value
Unknown
CVE-2022-27625
Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the message processing functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
0
Attacker Value
Unknown
CVE-2022-27624
Disclosure Date: October 20, 2022 (last updated January 15, 2025)
A vulnerability regarding improper restriction of operations within the bounds of a memory buffer is found in the packet decryption functionality of Out-of-Band (OOB) Management. This allows remote attackers to execute arbitrary commands via unspecified vectors. The following models with Synology DiskStation Manager (DSM) versions before 7.1.1-42962-2 may be affected: DS3622xs+, FS3410, and HD6500.
0
Attacker Value
Unknown
CVE-2022-27616
Disclosure Date: July 28, 2022 (last updated January 15, 2025)
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 7.0.1-42218-3 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22684
Disclosure Date: July 28, 2022 (last updated January 15, 2025)
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-27610
Disclosure Date: July 25, 2022 (last updated October 07, 2023)
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22688
Disclosure Date: March 21, 2022 (last updated January 15, 2025)
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22687
Disclosure Date: March 21, 2022 (last updated January 15, 2025)
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2022-22680
Disclosure Date: January 24, 2022 (last updated January 15, 2025)
Exposure of sensitive information to an unauthorized actor vulnerability in Web Server in Synology DiskStation Manager (DSM) before 7.0.1-42218-2 allows remote attackers to obtain sensitive information via unspecified vectors.
0