CVE-2024-10442
CRITICALDescription
Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via unspecified vectors.
Is your site exposed to CVE-2024-10442?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| synology | unified_controller |
| synology | diskstation_manager_unified_controller |
| synology | replication_service |
| synology | diskstation_manager |
| synology | replication_service |
| synology | diskstation_manager |
| syncology | replication_service |
| synology | diskstation_manager |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-10442? +
How severe is CVE-2024-10442? +
What products are affected by CVE-2024-10442? +
How do I check if I'm vulnerable to CVE-2024-10442? +
Related Vulnerabilities
Unsigned integer underflow in wstrncat() in src/port.c in wolfSSL wolfSSH from v1.4.11 through v1.5.0 on non-Windows platforms allows an authenticated …
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula …
Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from …
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH …
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow …
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their privileges to …