Qnap

Qts

272 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.5%
  • Veröffentlicht 28.11.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:43

Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the NAS.

  • EPSS 0.92%
  • Veröffentlicht 28.11.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:44

NULL Pointer Dereference vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to crash the NAS media server.

  • EPSS 0.62%
  • Veröffentlicht 28.11.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:44

Improper Authorization vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to power off the NAS.

  • EPSS 0.54%
  • Veröffentlicht 28.11.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:44

Buffer Overflow vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could have unspecified impact on the NAS.

  • EPSS 1.26%
  • Veröffentlicht 27.11.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:48

Buffer Overflow vulnerability in NAS devices. QTS allows attackers to run arbitrary code. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 ...

  • EPSS 0.23%
  • Veröffentlicht 27.11.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:48

Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on ...

  • EPSS 0.27%
  • Veröffentlicht 21.06.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:10:54

Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.

  • EPSS 2.6%
  • Veröffentlicht 21.06.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:47

Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or install malware on the NAS.

  • EPSS 0.23%
  • Veröffentlicht 30.04.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:47

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

  • EPSS 0.23%
  • Veröffentlicht 27.03.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:19

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware version and running services) via a request to sysinfoReq.cgi.