Isync Project maintains a small suite of mail-synchronization and routing tools, including isync and mrouter, that handle message parsing and protocol state management in focused email infrastructure roles. The observed vulnerability profile centers on memory-safety and type-handling issues such as buffer-boundary violations, incorrect type conversions, and out-of-bounds writes, which are typical of native-code implementations handling untrusted protocol data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Isync Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44143CRITICAL A flaw was found in mbsync in isync 1.4.0 through 1.4.3. Due to an unchecked condition, a malicious or compromised IMAP server could use a crafted mail message that lacks headers ( | Nov 22, 2021 | 9.8 | 33 | NO | NO |
CVE-2021-3657CRITICAL A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically | Feb 18, 2022 | 9.8 | 32 | NO | NO |
CVE-2005-0193HIGH Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code. | Jan 22, 2005 | 7.2 | 30 | NO | YES |
CVE-2021-3578HIGH A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a | Feb 16, 2022 | 7.8 | 26 | NO | NO |
CVE-2013-0289MEDIUM Isync 0.4 before 1.0.6, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which all | May 23, 2014 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Isync Project.
Media articles that mention a CVE ID that affects a product developed by Isync Project — matched by CVE ID, not by vendor name.