VendorsSynologydns_serverany version
Vulnerabilities

Synology DNS Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-27615
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.
Published 2022-07-28 · Modified
8.1EPSS 0.012
CVE-2020-8623
A flaw in native PKCS#11 code can lead to a remotely triggerable assertion failure in pk11.c
Published 2020-08-21 · Modified
7.5EPSS 0.064
CVE-2020-8621
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
Published 2020-08-21 · Modified
7.5EPSS 0.030
CVE-2020-8622
A truncated TSIG response can lead to an assertion failure
Published 2020-08-21 · Modified
6.5EPSS 0.056
CVE-2017-12074
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
Published 2017-08-24 · Modified
6.5EPSS 0.020