Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Isync Project

First CVE: Jan 22, 2005Active for: 22 yearsTotal CVEs: 5

Isync Project maintains a small suite of mail-synchronization and routing tools, including isync and mrouter, that handle message parsing and protocol state management in focused email infrastructure roles. The observed vulnerability profile centers on memory-safety and type-handling issues such as buffer-boundary violations, incorrect type conversions, and out-of-bounds writes, which are typical of native-code implementations handling untrusted protocol data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 79% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Isync Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2005
21 years ago
Most Recent CVE
Feb 18, 2022
1,617 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44143CRITICAL
A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers (
Nov 22, 20219.833NONO
CVE-2021-3657CRITICAL
A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically
Feb 18, 20229.832NONO
CVE-2005-0193HIGH
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.
Jan 22, 20057.230NOYES
CVE-2021-3578HIGH
A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a
Feb 16, 20227.826NONO
CVE-2013-0289MEDIUM
Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all
May 23, 20144.319NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
20%
40%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (20.0%)
Network2 (40.0%)
Unknown2 (40.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High0 (0.0%)
Unknown2 (40.0%)
User Interaction
None3 (60.0%)
Unknown2 (40.0%)
Required0 (0.0%)
Privileges Required
Low1 (20.0%)
High0 (0.0%)
None2 (40.0%)
Unknown2 (40.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
20.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Isync Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Isync Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Isync Project's Products

View all 3 CNAs →

Top CWEs