Show filters
88 Total Results
Displaying 61-70 of 88
Sort by:
Attacker Value
Unknown
CVE-2017-16774
Disclosure Date: April 01, 2019 (last updated January 15, 2025)
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.
0
Attacker Value
Unknown
CVE-2018-13286
Disclosure Date: April 01, 2019 (last updated January 15, 2025)
Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
0
Attacker Value
Unknown
CVE-2018-13293
Disclosure Date: April 01, 2019 (last updated January 15, 2025)
Cross-site scripting (XSS) vulnerability in Control Panel SSO Settings in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to inject arbitrary web script or HTML via the URL parameter.
0
Attacker Value
Unknown
CVE-2018-13284
Disclosure Date: April 01, 2019 (last updated January 15, 2025)
Command injection vulnerability in ftpd in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
0
Attacker Value
Unknown
CVE-2018-13291
Disclosure Date: April 01, 2019 (last updated January 15, 2025)
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology DiskStation Manager (DSM) before 6.2.1-23824 allows remote authenticated users to obtain sensitive information via the world readable configuration.
0
Attacker Value
Unknown
CVE-2018-8917
Disclosure Date: December 24, 2018 (last updated January 15, 2025)
Cross-site scripting (XSS) vulnerability in info.cgi in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary web script or HTML via the host parameter.
0
Attacker Value
Unknown
CVE-2018-8920
Disclosure Date: December 24, 2018 (last updated January 15, 2025)
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to inject arbitrary content to have an unspecified impact by exporting an archive in CSV format.
0
Attacker Value
Unknown
CVE-2018-8919
Disclosure Date: December 24, 2018 (last updated January 15, 2025)
Information exposure vulnerability in SYNO.Core.Desktop.SessionData in Synology DiskStation Manager (DSM) before 6.1.6-15266 allows remote attackers to steal credentials via unspecified vectors.
0
Attacker Value
Unknown
CVE-2018-1160
Disclosure Date: December 20, 2018 (last updated January 15, 2025)
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.
0
Attacker Value
Unknown
CVE-2018-13281
Disclosure Date: October 31, 2018 (last updated January 15, 2025)
Information exposure vulnerability in SYNO.Core.ACL in Synology DiskStation Manager (DSM) before 6.2-23739-2 allows remote authenticated users to determine the existence and obtain the metadata of arbitrary files via the file_path parameter.
0