Aggregator
CVE-2024-57767 | MSFM prior 2025.01.01 /file/download server-side request forgery
1 year 3 months ago
A vulnerability has been found in MSFM and classified as critical. This vulnerability affects unknown code of the file /file/download. The manipulation leads to server-side request forgery.
This vulnerability was named CVE-2024-57767. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2020-27656 | Synology DiskStation Manager up to 6.2.3-2541 DDNS channel accessible (SA_20_18)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Synology DiskStation Manager up to 6.2.3-2541. Affected is an unknown function of the component DDNS. The manipulation leads to channel accessible by non-endpoint.
This vulnerability is traded as CVE-2020-27656. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26560 | Synology DiskStation Manager up to 6.2.3-25423 HTTP Session channel accessible (SA_20_26)
1 year 3 months ago
A vulnerability classified as problematic has been found in Synology DiskStation Manager. Affected is an unknown function of the component HTTP Session Handler. The manipulation leads to channel accessible by non-endpoint.
This vulnerability is traded as CVE-2021-26560. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26561 | Synology DiskStation Manager up to 6.2.3-25423 HTTP Header syno_finder_site stack-based overflow (SA_20_26)
1 year 3 months ago
A vulnerability classified as critical was found in Synology DiskStation Manager. Affected by this vulnerability is an unknown functionality of the component HTTP Header Handler. The manipulation of the argument syno_finder_site leads to stack-based buffer overflow.
This vulnerability is known as CVE-2021-26561. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26562 | Synology DiskStation Manager up to 6.2.3-25423 HTTP Header syno_finder_site out-of-bounds write (SA_20_26)
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in Synology DiskStation Manager. Affected by this issue is some unknown functionality of the component HTTP Header Handler. The manipulation of the argument syno_finder_site leads to out-of-bounds write.
This vulnerability is handled as CVE-2021-26562. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26563 | Synology DiskStation Manager up to 6.2.3-25423 Kernel Module access control (SA_20_26)
1 year 3 months ago
A vulnerability, which was classified as problematic, was found in Synology DiskStation Manager. This affects an unknown part of the component Kernel Module Handler. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2021-26563. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26564 | Synology DiskStation Manager up to 6.2.3-25423 HTTP Session channel accessible (SA_20_26)
1 year 3 months ago
A vulnerability has been found in Synology DiskStation Manager and classified as problematic. This vulnerability affects unknown code of the component HTTP Session Handler. The manipulation leads to channel accessible by non-endpoint.
This vulnerability was named CVE-2021-26564. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26565 | Synology DiskStation Manager up to 6.2.3-25423 HTTP Session cleartext transmission (SA_20_26)
1 year 3 months ago
A vulnerability was found in Synology DiskStation Manager and classified as problematic. This issue affects some unknown processing of the component HTTP Session Handler. The manipulation leads to cleartext transmission of sensitive information.
The identification of this vulnerability is CVE-2021-26565. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26566 | Synology DiskStation Manager up to 6.2.3-25423 synorelayd insertion of sensitive information into sent data (SA_20_26)
1 year 3 months ago
A vulnerability was found in Synology DiskStation Manager. It has been classified as critical. Affected is an unknown function of the component synorelayd. The manipulation leads to insertion of sensitive information into sent data.
This vulnerability is traded as CVE-2021-26566. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26567 | Synology DiskStation Manager up to 6.2.3-25423 faad path traversal (SA_20_26)
1 year 3 months ago
A vulnerability was found in Synology DiskStation Manager. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component faad. The manipulation leads to path traversal.
This vulnerability is known as CVE-2021-26567. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-26569 | Synology DiskStation Manager up to 6.2.3-25423 Thread iscsi_snapshot_comm_core race condition (SA_20_26)
1 year 3 months ago
A vulnerability was found in Synology DiskStation Manager. It has been rated as critical. Affected by this issue is the function iscsi_snapshot_comm_core of the component Thread Handler. The manipulation leads to race condition.
This vulnerability is handled as CVE-2021-26569. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27646 | Synology DiskStation Manager up to 6.2.3-25423 Web Request iscsi_snapshot_comm_core use after free (SA_20_26)
1 year 3 months ago
A vulnerability classified as critical has been found in Synology DiskStation Manager. This affects the function iscsi_snapshot_comm_core of the component Web Request Handler. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2021-27646. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-27647 | Synology DiskStation Manager up to 6.2.3-25423 Web Request iscsi_snapshot_comm_core out-of-bounds (SA_20_26)
1 year 3 months ago
A vulnerability classified as critical was found in Synology DiskStation Manager. This vulnerability affects the function iscsi_snapshot_comm_core of the component Web Request Handler. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2021-27647. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2002-2343 | NOCC up to 0.9.5 Email Message cross site scripting (EDB-21449 / XFDB-9071)
1 year 3 months ago
A vulnerability was found in NOCC up to 0.9.5 and classified as problematic. This issue affects some unknown processing of the component Email Message Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2002-2343. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation
1 year 3 months ago
Malware / Threat IntelligenceThe U.S. Department of Justice (DoJ) on Tuesday disclosed that a cou
FBI Deletes PlugX Malware from 4,250 Hacked Computers in Multi-Month Operation
1 year 3 months ago
The U.S. Department of Justice (DoJ) on Tuesday disclosed that a court-authorized operation allowed the Federal Bureau of Investigation (FBI) to delete PlugX malware from over 4,250 infected computers as part of a "multi-month law enforcement operation."
PlugX, also known as Korplug, is a remote access trojan (RAT) widely used by threat actors associated with the People's Republic of China (PRC
The Hacker News
Цукерберг: ИИ заменит программистов в Meta уже в 2025 году
1 year 3 months ago
Глава компании рассказал о планах автоматизировать процессы разработки.
CVE-2024-57483 | Tenda i24 2.0.0.5 addWifiMacFilter buffer overflow
1 year 3 months ago
A vulnerability, which was classified as critical, was found in Tenda i24 2.0.0.5. This affects the function addWifiMacFilter. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2024-57483. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2024-57765 | MSFM prior 2025.01.01 table/list s_name sql injection
1 year 3 months ago
A vulnerability, which was classified as critical, has been found in MSFM. Affected by this issue is some unknown functionality of the file table/list. The manipulation of the argument s_name leads to sql injection.
This vulnerability is handled as CVE-2024-57765. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com