VYPR

Media Server

by Synology

CVEs (6)

  • CVE-2022-22683CriJul 28, 2022
    risk 0.65cvss 10.0epss 0.02

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2024-4464HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

  • CVE-2021-33180HigJun 1, 2021
    risk 0.48cvss 7.3epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-8914HigMay 10, 2018
    risk 0.48cvss 7.3epss 0.01

    SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.

  • CVE-2021-34808MedJun 18, 2021
    risk 0.38cvss 5.8epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors.

  • CVE-2022-27614MedJul 28, 2022
    risk 0.35cvss 5.3epss 0.01

    Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors.