CVE-2024-50395
- EPSS 8.61%
- Veröffentlicht 22.11.2024 16:15:32
- Zuletzt bearbeitet 22.11.2024 16:15:32
An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in t...
CVE-2023-47220
- EPSS 0.27%
- Veröffentlicht 03.05.2024 03:16:01
- Zuletzt bearbeitet 21.11.2024 08:29:58
An OS command injection vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the foll...
CVE-2023-47222
- EPSS 0.15%
- Veröffentlicht 26.04.2024 15:15:46
- Zuletzt bearbeitet 21.11.2024 08:29:59
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability ...
CVE-2023-23369
- EPSS 14.77%
- Veröffentlicht 03.11.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:02
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following v...
CVE-2021-34362
- EPSS 0.87%
- Veröffentlicht 22.10.2021 05:15:41
- Zuletzt bearbeitet 21.11.2024 06:10:14
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following ver...
CVE-2020-36195
- EPSS 2.02%
- Veröffentlicht 17.04.2021 04:15:11
- Zuletzt bearbeitet 21.11.2024 05:28:59
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulne...
CVE-2017-7634
- EPSS 0.25%
- Veröffentlicht 08.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:20
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted li...
CVE-2017-7638
- EPSS 0.19%
- Veröffentlicht 08.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:20
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not authenticate requests properly. Successful exploitation could lead to change of the Media Streaming settings, and leakage of sensitive information of the Q...
- EPSS 2.3%
- Veröffentlicht 08.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:21
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
CVE-2017-7641
- EPSS 0.16%
- Veröffentlicht 08.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:21
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier does not utilize CSRF protections.