CVE-2020-27654
- EPSS 3.05%
- Veröffentlicht 29.10.2020 09:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:36
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27653
- EPSS 0.5%
- Veröffentlicht 29.10.2020 09:15:13
- Zuletzt bearbeitet 14.01.2025 19:29:55
Algorithm downgrade vulnerability in QuickConnect in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
CVE-2020-27651
- EPSS 0.33%
- Veröffentlicht 29.10.2020 09:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:35
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
- EPSS 0.18%
- Veröffentlicht 29.10.2020 09:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:35
Improper certificate validation vulnerability in OpenVPN client in Synology Router Manager (SRM) before 1.2.4-8081 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2019-11823
- EPSS 1.1%
- Veröffentlicht 04.05.2020 10:15:10
- Zuletzt bearbeitet 21.11.2024 04:21:50
CRLF injection vulnerability in Network Center in Synology Router Manager (SRM) before 1.2.3-8017-2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted network traffic.
CVE-2019-9502
- EPSS 1.91%
- Veröffentlicht 03.02.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:51:44
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is larger than 164 bytes, a heap buffer overflow is triggered in wlc_wpa_plumb_gtk. In the worst case scenario, by sending specially-cr...
CVE-2019-9501
- EPSS 3.06%
- Veröffentlicht 03.02.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:51:44
The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a data length larger than 32 bytes, a heap buffer overflow is triggered in wlc_wpa_sup_eapol. In the worst case scenario, by sending s...
CVE-2019-19344
- EPSS 2.31%
- Veröffentlicht 21.01.2020 18:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
There is a use-after-free issue in all samba 4.9.x versions before 4.9.18, all samba 4.10.x versions before 4.10.12 and all samba 4.11.x versions before 4.11.5, essentially due to a call to realloc() while other local variables still point at the ori...
CVE-2019-14907
- EPSS 10.24%
- Veröffentlicht 21.01.2020 18:15:12
- Zuletzt bearbeitet 14.01.2025 19:29:55
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such st...
CVE-2019-9499
- EPSS 1.06%
- Veröffentlicht 17.04.2019 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:51:44
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication,...