Vulnerabilities > Qnap > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-21 CVE-2017-17030 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qnap QTS
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
network
low complexity
qnap CWE-119
7.5
2017-12-21 CVE-2017-17029 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qnap QTS
A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
network
low complexity
qnap CWE-119
7.5
2017-12-21 CVE-2017-17028 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qnap QTS
A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
network
low complexity
qnap CWE-119
7.5
2017-12-21 CVE-2017-17027 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Qnap QTS
A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.
network
low complexity
qnap CWE-119
7.5
2017-11-22 CVE-2017-13071 Command Injection vulnerability in Qnap Video Station 5.1.3/5.2.0
QNAP has already patched this vulnerability.
network
low complexity
qnap CWE-77
7.5
2017-10-06 CVE-2017-13069 Command Injection vulnerability in Qnap Music Station
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier.
network
low complexity
qnap CWE-77
7.5
2017-09-14 CVE-2017-13067 Unspecified vulnerability in Qnap QTS
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901.
network
low complexity
qnap
7.5
2017-08-18 CVE-2017-12582 Missing Authorization vulnerability in Qnap Ts-212P Firmware 4.2.1
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601.
network
low complexity
qnap CWE-862
7.5
2017-06-15 CVE-2017-7876 Command Injection vulnerability in Qnap QTS
This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application.
network
low complexity
qnap CWE-77
7.5
2016-02-27 CVE-2015-7262 Source Code vulnerability in Qnap Iartist Lite and Signage Station
QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.
network
qnap CWE-18
8.5