
CVE-2017-17028 – QNAP QTS Web devRequest Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17028
20 Dec 2017 — A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función del dispositivo externo en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en ... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17029 – QNAP QTS authLogin Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17029
20 Dec 2017 — A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función de inicio de sesión en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en los dispositiv... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17030 – QNAP QTS authLogin Host Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17030
20 Dec 2017 — A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función de inicio de sesión en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en los dispositiv... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17031 – QNAP QTS Web change_password Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17031
20 Dec 2017 — A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función de contraseña en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en los dispositivos ... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17032 – QNAP QTS Web change_password Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17032
20 Dec 2017 — A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función de contraseña en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en los dispositivos ... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-17033 – QNAP QTS Web sysinfoReq Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2017-17033
20 Dec 2017 — A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices. Una vulnerabilidad de desbordamiento de búfer en la función de contraseña en QNAP QTS 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 y anteriores podría permitir que los atacantes remotos ejecuten código arbitrario en los dispositivos ... • http://www.securitytracker.com/id/1040018 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2017-7629
https://notcve.org/view.php?id=CVE-2017-7629
15 Jun 2017 — QNAP QTS before 4.2.6 build 20170517 has a flaw in the change password function. QNAP QTS anterior a versión 4.2.6, build 20170517, presenta un fallo en la función change password. • https://www.qnap.com/en-us/releasenotes • CWE-640: Weak Password Recovery Mechanism for Forgotten Password •

CVE-2017-7876
https://notcve.org/view.php?id=CVE-2017-7876
15 Jun 2017 — This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. QNAP have already fixed the issue in QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 and later versions. Esta vulnerabilidad de inyección de comandos en el QTS permite a los atacantes ejecutar comandos arbitrarios en la aplicación comprometida. QNAP ya ha solucionado el problema en QTS 4.2.6 build 20170517, QTS 4.3.3.0174 build 20170503 y versiones posteriores • https://www.qnap.com/en/release-notes/qts/4.2.6/20170517 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2017-6361 – QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
https://notcve.org/view.php?id=CVE-2017-6361
23 Mar 2017 — QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. QNAP QTS en versiones anteriores a 4.2.4 revisión 20170313 permite a atacantes ejecutar comandos arbitrarios a través de vectores no especificados. QNAP QTS suffers from multiple command injection vulnerabilities. • https://packetstorm.news/files/id/142036 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2017-6359 – QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
https://notcve.org/view.php?id=CVE-2017-6359
23 Mar 2017 — QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors. QNAP QTS en versiones anteriores a 4.2.4 revisión 20170313 permite a atacantes remotos obtener privilegios de administrador y ejecutar comandos arbitrarios a través de vectores no especificados. QNAP QTS suffers from multiple command injection vulnerabilities. • https://packetstorm.news/files/id/142036 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •