CVE-2019-9498
- EPSS 1.06%
- Veröffentlicht 17.04.2019 14:29:04
- Zuletzt bearbeitet 21.11.2024 04:51:44
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar...
CVE-2019-9495
- EPSS 6.03%
- Veröffentlicht 17.04.2019 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:51:43
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execu...
CVE-2019-9494
- EPSS 1.54%
- Veröffentlicht 17.04.2019 14:29:03
- Zuletzt bearbeitet 21.11.2024 04:51:43
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that...
CVE-2019-3870
- EPSS 0.46%
- Veröffentlicht 09.04.2019 16:29:01
- Zuletzt bearbeitet 14.01.2025 19:29:55
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700,...
CVE-2018-13292
- EPSS 0.31%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:46
Information exposure vulnerability in /usr/syno/etc/mount.conf in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to obtain sensitive information via the world readable configuration.
CVE-2018-13290
- EPSS 0.31%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:46
Information exposure vulnerability in SYNO.Core.ACL in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote authenticated users to determine the existence of files or obtain sensitive information of files via the file_path parameter.
CVE-2018-13289
- EPSS 0.45%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:46
Information exposure vulnerability in SYNO.FolderSharing.List in Synology Router Manager (SRM) before 1.1.7-6941-2 allows remote attackers to obtain sensitive information via the (1) folder_path or (2) real_path parameter.
CVE-2018-13287
- EPSS 0.28%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:45
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration.
- EPSS 0.69%
- Veröffentlicht 01.04.2019 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:45
Command injection vulnerability in ftpd in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to execute arbitrary OS commands via the (1) MKD or (2) RMD command.
CVE-2018-8918
- EPSS 0.14%
- Veröffentlicht 24.12.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:14:36
Cross-site scripting (XSS) vulnerability in info.cgi in Synology Router Manager (SRM) before 1.1.7-6941 allows remote attackers to inject arbitrary web script or HTML via the host parameter.