CVE-2022-27615
- EPSS 0.7%
- Veröffentlicht 28.07.2022 04:15:09
- Zuletzt bearbeitet 21.11.2024 06:56:01
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
CVE-2020-8621
- EPSS 4.22%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that ...
CVE-2020-8622
- EPSS 0.6%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed re...
CVE-2020-8623
- EPSS 5.63%
- Veröffentlicht 21.08.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:08
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To ...
CVE-2017-12074
- EPSS 0.42%
- Veröffentlicht 24.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.