Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2021-36668
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.
0
Attacker Value
Unknown
CVE-2021-36667
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
0
Attacker Value
Unknown
CVE-2021-36666
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
0
Attacker Value
Unknown
CVE-2021-36665
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.
0
Attacker Value
Unknown
CVE-2020-5798
Disclosure Date: December 07, 2020 (last updated February 22, 2025)
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory permissions.
0
Attacker Value
Unknown
CVE-2020-5752
Disclosure Date: May 21, 2020 (last updated February 21, 2025)
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
0
Attacker Value
Unknown
CVE-2019-4001
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.
0
Attacker Value
Unknown
CVE-2019-4000
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
0
Attacker Value
Unknown
CVE-2019-3999
Disclosure Date: February 25, 2020 (last updated February 21, 2025)
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
0