NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
27685  CVE-2015-6909  Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.    4.3  Medium  2017-01-19  2015-09-14  View
27686  CVE-2015-6910  SQL injection vulnerability in Synology Video Station before 1.5-0757 allows remote attackers to execute arbitrary SQL commands via the id parameter to audiotrack.cgi.    7.5  High  2017-01-19  2015-09-14  View
27687  CVE-2015-6911  SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL commands via the id parameter to watchstatus.cgi.    7.5  High  2017-01-19  2015-09-14  View
27688  CVE-2015-6912  Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.    10  High  2017-01-19  2015-09-14  View
27689  CVE-2015-6913  Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.    4.3  Medium  2017-01-19  2015-09-14  View

Page 14860 of 17672, showing 5 records out of 88360 total, starting on record 74296, ending on 74300

Actions