Show filters
966 Total Results
Displaying 21-30 of 966
Sort by:
Attacker Value
Unknown
CVE-2024-48868
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.2.2952 build 20241116 and later
0
Attacker Value
Unknown
CVE-2024-48867
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to modify application data.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.2.2952 build 20241116 and later
0
Attacker Value
Unknown
CVE-2024-48866
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.2.2952 build 20241116 and later
0
Attacker Value
Unknown
CVE-2024-48865
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network access to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.2.2952 build 20241116 and later
0
Attacker Value
Unknown
CVE-2024-48859
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the security of the system.
We have already fixed the vulnerability in the following versions:
QTS 5.1.9.2954 build 20241120 and later
QTS 5.2.2.2950 build 20241114 and later
QuTS hero h5.1.9.2954 build 20241120 and later
QuTS hero h5.2.2.2952 build 20241116 and later
0
Attacker Value
Unknown
CVE-2024-43050
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while invoking IOCTL calls from user space to issue factory test command inside WLAN driver.
0
Attacker Value
Unknown
CVE-2024-33056
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
0
Attacker Value
Unknown
CVE-2024-33044
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
0
Attacker Value
Unknown
CVE-2018-11816
Disclosure Date: November 26, 2024 (last updated February 07, 2025)
Crafted Binder Request Causes Heap UAF in MediaServer
0
Attacker Value
Unknown
CVE-2024-50401
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory.
We have already fixed the vulnerability in the following versions:
QTS 5.2.1.2930 build 20241025 and later
QuTS hero h5.2.1.2929 build 20241025 and later
0