Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
insync client vulnerabilities and exploits
(subscribe to this query)
641
VMScore
CVE-2021-36666
An issue exists in Druva 6.9.0 for MacOS, allows malicious users to gain escalated local privileges via the inSyncDecommission.
Druva Insync Client
409
VMScore
CVE-2021-36668
URL injection in Driva inSync 6.9.0 for MacOS, allows malicious users to force a visit to an arbitrary url via the port parameter to the Electron App.
Druva Insync Client
641
VMScore
CVE-2021-36665
An issue exists in Druva 6.9.0 for macOS, allows malicious users to gain escalated local privileges via the inSyncUpgradeDaemon.
Druva Insync Client
409
VMScore
CVE-2021-36667
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows malicious users to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
Druva Insync Client
641
VMScore
CVE-2020-5752
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.6.3
1 Github repository
409
VMScore
CVE-2019-4001
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary NodeJS code.
Druva Insync 6.5.0
641
VMScore
CVE-2019-4000
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary Python expressions with root privileges.
Druva Insync 6.5.0
641
VMScore
CVE-2020-5798
inSync Client installer for macOS versions v6.8.0 and prior could allow an malicious user to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
Druva Insync 6.8.0
641
VMScore
CVE-2019-3999
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.5.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started