Show filters
375 Total Results
Displaying 41-50 of 375
Sort by:
Attacker Value
Unknown

CVE-2024-38646

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers who have gained administrator access to read or modify the resource. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
0
Attacker Value
Unknown

CVE-2024-38645

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
0
Attacker Value
Unknown

CVE-2024-38644

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
0
Attacker Value
Unknown

CVE-2024-38643

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
0
Attacker Value
Unknown

CVE-2024-37050

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0
Attacker Value
Unknown

CVE-2024-37049

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0
Attacker Value
Unknown

CVE-2024-37048

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0
Attacker Value
Unknown

CVE-2024-37047

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0
Attacker Value
Unknown

CVE-2024-37046

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensitive data. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0
Attacker Value
Unknown

CVE-2024-37045

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following versions: QTS 5.2.1.2930 build 20241025 and later QuTS hero h5.2.1.2929 build 20241025 and later
0