CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreNov 21, 2024 Sep 28, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a...Show more |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreNov 21, 2024 Sep 28, 2018 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As...Show more |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreNov 21, 2024 Sep 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cook...Show more |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreNov 21, 2024 Sep 28, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags an...Show more |
1Lenovo 20Ez Media & Backup Center Firmware Ix2 FirmwareIx4 300d Firmware+17 moreNov 21, 2024 Sep 28, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the dev...Show more |