Show filters
300 Total Results
Displaying 201-210 of 300
Sort by:
Attacker Value
Unknown
CVE-2018-8920
Disclosure Date: December 24, 2018 (last updated January 15, 2025)
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.
0
Attacker Value
Unknown
CVE-2018-8919
Disclosure Date: December 24, 2018 (last updated January 15, 2025)
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-8918
Disclosure Date: December 24, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
0
Attacker Value
Unknown
CVE-2018-1160
Disclosure Date: December 20, 2018 (last updated January 15, 2025)
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
0
Attacker Value
Unknown
CVE-2018-13281
Disclosure Date: October 31, 2018 (last updated January 15, 2025)
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
0
Attacker Value
Unknown
CVE-2018-13282
Disclosure Date: October 31, 2018 (last updated November 27, 2024)
Session fixation vulnerability in SYNO.PhotoStation.Auth in Synology Photo Station before 6.8.7-3481 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
0
Attacker Value
Unknown
CVE-2018-13280
Disclosure Date: July 30, 2018 (last updated January 15, 2025)
Use of insufficiently random values vulnerability in SYNO.Encryption.GenRandomKey in Synology DiskStation Manager (DSM) before 6.2-23739 allows man-in-the-middle attackers to compromise non-HTTPS sessions via unspecified vectors.
0
Attacker Value
Unknown
Synology NAS servers DS107, DS116, and DS213, use default credentials
Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vulnerable device.
0
Attacker Value
Unknown
CVE-2018-8929
Disclosure Date: July 06, 2018 (last updated November 27, 2024)
Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload.
0
Attacker Value
Unknown
CVE-2018-8928
Disclosure Date: July 05, 2018 (last updated November 27, 2024)
Cross-site scripting (XSS) vulnerability in Address Book Editor in Synology CardDAV Server before 6.0.8-0086 allows remote authenticated users to inject arbitrary web script or HTML via the (1) family_name, (2) given_name, or (3) additional_name parameter.
0