Skip to content
Noroxi

druva records

9 published records for vendor druva.

All records

9 records
  • CVE-2020-5752
    34Monitor

    Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system

    HighCVSS 7.8WeaponizedEPSS 9%

    druva · insync clientMay 21, 2020

  • CVE-2019-3999
    34Monitor

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attac

    HighCVSS 7.8WeaponizedEPSS 9%

    druva · insync clientFeb 25, 2020

  • Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the l

    HighCVSS 7.8No exploitEPSS 3%

    druva · insync clientJul 12, 2022

  • CVE-2019-4000
    31Monitor

    Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attack

    HighCVSS 7.8No exploitEPSS 1%

    druva · insyncFeb 25, 2020

  • URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron

    HighCVSS 7.8No exploitEPSS 1%

    druva · insync clientJul 12, 2022

  • CVE-2019-4001
    31Monitor

    Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJS code.

    HighCVSS 7.8No exploitEPSS 1%

    druva · insyncMar 24, 2020

  • An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon.

    HighCVSS 7.8No exploitEPSS 1%

    druva · insync clientJul 12, 2022

  • An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

    HighCVSS 7.8No exploitEPSS 0%

    druva · insync clientJul 12, 2022

  • CVE-2020-5798
    31Monitor

    inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privilege

    HighCVSS 7.8No exploitEPSS 0%

    druva · insyncDec 7, 2020