Show filters
300 Total Results
Displaying 231-240 of 300
Sort by:
Attacker Value
Unknown

CVE-2018-7184

Disclosure Date: March 06, 2018 (last updated January 15, 2025)
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
0
Attacker Value
Unknown

CVE-2018-7170

Disclosure Date: March 06, 2018 (last updated January 15, 2025)
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Attacker Value
Unknown

CVE-2017-16770

Disclosure Date: February 27, 2018 (last updated November 26, 2024)
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
0
Attacker Value
Unknown

CVE-2017-16767

Disclosure Date: February 27, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTML via the userDesc parameter.
0
Attacker Value
Unknown

CVE-2017-16769

Disclosure Date: February 23, 2018 (last updated November 26, 2024)
Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs via the map viewer mode.
0
Attacker Value
Unknown

CVE-2017-15892

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.
0
Attacker Value
Unknown

CVE-2017-15886

Disclosure Date: December 28, 2017 (last updated November 26, 2024)
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.
0
Attacker Value
Unknown

CVE-2017-16768

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
0
Attacker Value
Unknown

CVE-2017-16766

Disclosure Date: December 22, 2017 (last updated January 15, 2025)
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary web script or HTML via the -fn option.
0
Attacker Value
Unknown

CVE-2017-12072

Disclosure Date: December 20, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or HTML via the id parameter.
0