Skip to main content

Vendor/product archive

synology / diskstation_manager CVEs

Beta · best-effort

134 CVEs tagged to synology / diskstation_manager19 Critical, 46 High, 65 Medium, 4 Low, 0 Unrated.

CVE-2021-29088

Published Jun 1, 2021

Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to exec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29083

Published Apr 1, 2021

Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote authenticated…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27647

Published Mar 12, 2021

Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via craft…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-27646

Published Mar 12, 2021

Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted w…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26569

Published Mar 12, 2021

Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27656

Published Oct 29, 2020

Cleartext transmission of sensitive information vulnerability in DDNS in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to eavesdrop au…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14907

Published Jan 21, 2020

All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained fr…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Showing 76-100 of 134 CVEsPage 4 of 6