Skip to main content

Vendor archive

synology CVEs

Beta · best-effort

349 CVEs tagged to vendor synology39 Critical, 120 High, 183 Medium, 7 Low, 0 Unrated.

CVE-2017-16772

Published Mar 22, 2018

Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execut…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16771

Published Mar 22, 2018

Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HT…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-7184

Published Mar 6, 2018

ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending…

CVSS 7.5 · High

CVE-2017-16770

Published Feb 27, 2018

File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authentic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16767

Published Feb 27, 2018

Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to inject arbitrary web script or HTM…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16769

Published Feb 23, 2018

Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadata from password-protected photographs v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15892

Published Dec 28, 2017

Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15886

Published Dec 28, 2017

Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a craft…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16768

Published Dec 27, 2017

Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the nam…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16766

Published Dec 22, 2017

An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 allows local users to inject arbitrary w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12072

Published Dec 20, 2017

Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.8.0-3456 allows remote authenticated users to inject arbitrary web scripts or…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15890

Published Dec 15, 2017

Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via t…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15895

Published Dec 8, 2017

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology Router Manager (SRM) before 1.1.5-6542-4 allows remote authenticated users to write arbitrary files v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15894

Published Dec 8, 2017

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology DiskStation Manager (DSM) 6.0.x before 6.0.3-8754-3 and before 5.2-5967-6 allows remote authenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15893

Published Dec 8, 2017

Directory traversal vulnerability in the SYNO.FileStation.Extract in Synology File Station before 1.1.1-0099 allows remote authenticated users to write arbitrary files via the des…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15891

Published Dec 8, 2017

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vecto…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-15889

Published Dec 4, 2017

Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authenticated users to execute arbitrary commands via disk field.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12080

Published Dec 4, 2017

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitiv…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12079

Published Dec 4, 2017

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-15887

Published Nov 7, 2017

An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user crede…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15888

Published Oct 30, 2017

Cross-site scripting (XSS) vulnerability in Custom Internet Radio List in Synology Audio Station before 6.3.0-3260 allows remote authenticated attackers to inject arbitrary web sc…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-12071

Published Sep 8, 2017

Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-11162

Published Sep 8, 2017

Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 349 CVEsPage 12 of 14