VYPR

Synology

by Synology

CVEs (7)

  • CVE-2024-10443CriNov 15, 2024
    risk 0.66cvss 9.8epss 0.28

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute…

  • CVE-2020-27660CriNov 30, 2020
    risk 0.63cvss 9.6epss 0.05

    SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.

  • CVE-2017-15886MedDec 28, 2017
    risk 0.42cvss 6.5epss 0.02

    Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.04

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2018-13297MedApr 1, 2019
    risk 0.35cvss 5.3epss 0.01

    Information exposure vulnerability in SYNO.SynologyDrive.Files in Synology Drive before 1.1.2-10562 allows remote attackers to obtain sensitive system information via the dsm_path parameter.

  • CVE-2017-15892MedDec 28, 2017
    risk 0.35cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.

  • CVE-2019-14847MedNov 6, 2019
    risk 0.32cvss 4.9epss 0.02

    A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issue.