VYPR

Synology Media Server

by Synology

CVEs (5)

  • CVE-2022-22683CriJul 28, 2022
    risk 0.65cvss 10.0epss 0.02

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2024-4464HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

  • CVE-2018-8914HigMay 10, 2018
    risk 0.48cvss 7.3epss 0.01

    SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.

  • CVE-2025-2848MedDec 4, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions.

  • CVE-2022-27614MedJul 28, 2022
    risk 0.35cvss 5.3epss 0.01

    Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.