Show filters
300 Total Results
Displaying 221-230 of 300
Sort by:
Attacker Value
Unknown

CVE-2018-8921

Disclosure Date: June 01, 2018 (last updated October 18, 2024)
Cross-site scripting (XSS) vulnerability in File Sharing Notify Toast in Synology Drive before 1.0.2-10275 allows remote authenticated users to inject arbitrary web script or HTML via the malicious file name.
0
Attacker Value
Unknown

CVE-2018-8915

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter.
0
Attacker Value
Unknown

CVE-2018-8910

Disclosure Date: May 10, 2018 (last updated October 18, 2024)
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
0
Attacker Value
Unknown

CVE-2018-8914

Disclosure Date: May 10, 2018 (last updated November 26, 2024)
SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.
0
Attacker Value
Unknown

CVE-2018-8912

Disclosure Date: May 09, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Note in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via the commit_msg parameter.
0
Attacker Value
Unknown

CVE-2018-8911

Disclosure Date: May 09, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
0
Attacker Value
Unknown

CVE-2018-8897

Disclosure Date: May 08, 2018 (last updated November 26, 2024)
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that tra…
0
Attacker Value
Unknown

CVE-2017-16772

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes via the prog_id parameter.
0
Attacker Value
Unknown

CVE-2017-16771

Disclosure Date: March 22, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
0
Attacker Value
Unknown

CVE-2018-7185

Disclosure Date: March 06, 2018 (last updated January 15, 2025)
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.