Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
insync client vulnerabilities and exploits
(subscribe to this query)
641
VMScore
CVE-2021-36665
An issue exists in Druva 6.9.0 for macOS, allows malicious users to gain escalated local privileges via the inSyncUpgradeDaemon.
Druva Insync Client
641
VMScore
CVE-2021-36666
An issue exists in Druva 6.9.0 for MacOS, allows malicious users to gain escalated local privileges via the inSyncDecommission.
Druva Insync Client
409
VMScore
CVE-2021-36667
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows malicious users to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
Druva Insync Client
409
VMScore
CVE-2021-36668
URL injection in Driva inSync 6.9.0 for MacOS, allows malicious users to force a visit to an arbitrary url via the port parameter to the Electron App.
Druva Insync Client
641
VMScore
CVE-2020-5752
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.6.3
1 Github repository
409
VMScore
CVE-2019-4001
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary NodeJS code.
Druva Insync 6.5.0
641
VMScore
CVE-2019-4000
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated malicious user to execute arbitrary Python expressions with root privileges.
Druva Insync 6.5.0
641
VMScore
CVE-2020-5798
inSync Client installer for macOS versions v6.8.0 and prior could allow an malicious user to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
Druva Insync 6.8.0
641
VMScore
CVE-2019-3999
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated malicious user to execute arbitrary operating system commands with SYSTEM privileges.
Druva Insync Client 6.5.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started