Sync Breeze

Vendor:

First CVE: Mar 29, 2017 · Active for 9 years

24
Total CVEs
Bottom 1%
8.0
Avg CVEs / Year
Bottom 1%
7.5
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sync Breeze over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2017
9 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

CVE Severity & Scoring

Sync Breeze24 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local5 (20.8%)
Network19 (79.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (50.0%)
Unknown0 (0.0%)
Required12 (50.0%)
Privileges Required
Low13 (54.2%)
High0 (0.0%)
None11 (45.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be trigge
Mar 12, 20187.582NOYES
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterpr
Jan 24, 20189.881NOYES
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout bef
Mar 29, 20177.874NOYES
Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.
Oct 10, 20179.853NOYES
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests
Dec 19, 20177.538NOYES
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary code execution. The flaw is triggered by providing a long inpu
Oct 31, 20177.838NOYES
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to cont
Jan 10, 20187.535NOYES
A buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute arbitrary code by sending a crafted packet to
Feb 2, 20189.832NONO
There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive
Dec 3, 20177.829NONO
A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14. The vulnerability can be triggered by an authenticated attacker
Feb 6, 20188.827NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
16.7% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
20.8% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Sync Breeze

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.9.1619.879.3%01
9.5.1617.853.6%01
13.6.1817.80.2%00
12.4.1817.80.2%00
10.6.2417.576.3%01
10.4.18116.90.5%00
10.1.1637.78.8%02
10.0.2828.711.6%01