VulnSea

insync_client vulnerabilities

CVEs whose affected-version data names the insync_client package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2021-36668High· 7.8
4y ago

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

Twilightdruva · insync_clientEPSS 0.58%via NVD
CVE-2021-36667High· 7.8
4y ago

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.

Twilightdruva · insync_clientEPSS 2.7%via NVD
CVE-2021-36666High· 7.8
4y ago

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

Twilightdruva · insync_clientEPSS 0.46%via NVD
CVE-2021-36665High· 7.8
4y ago

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

Twilightdruva · insync_clientEPSS 0.51%via NVD
insync_client vulnerabilities (CVEs) · VulnSea