Palm's vulnerability footprint centers on its mobile operating system and related desktop synchronization products, which, despite a narrow product scope, achieved notable deployment in early handheld and smartphone devices. While the vendor's disclosed vulnerabilities are modestly represented in the landscape, they have a tendency toward public exploit availability, reflecting the appeal of these devices as targets for malware and unauthorized access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Palm over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0293MEDIUM PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets. | Jun 16, 2003 | 5.0 | 24 | NO | YES |
CVE-2000-1008MEDIUM PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to | Dec 11, 2000 | 4.6 | 21 | NO | YES |
CVE-2007-4213HIGH Palm OS on Treo 650, 680, 700p, and 755p Smart phones allows remote attackers to cause a denial of service (device reset or hang) via a flood of large ICMP echo requests. NOTE: th | Aug 21, 2007 | 7.1 | 19 | NO | NO |
CVE-2002-0116MEDIUM Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nm | Mar 25, 2002 | 5.0 | 15 | NO | NO |
CVE-2001-1438MEDIUM Handspring Visor 1.0 and 1.0.1 with the VisorPhone Springboard module installed allows remote attackers to cause a denial of service (PalmOS crash and VisorPhone database corruptio | Oct 22, 2001 | 5.0 | 15 | NO | NO |
CVE-2001-0157MEDIUM Debugging utility in the backdoor mode of Palm OS 3.5.2 and earlier allows attackers with physical access to a Palm device to bypass access restrictions and obtain passwords, even | Jun 2, 2001 | 4.6 | 14 | NO | NO |
The Find feature in Palm OS Treo smart phones operates despite the system password lock, which allows attackers with physical access to obtain sensitive information (memory content | Feb 16, 2007 | 2.1 | 11 | NO | NO |
Apple Palm Desktop 4.0b76 and 4.0b77 creates world-readable backup files and folders when a hotsync is performed, which could allow a local user to obtain sensitive information. | Mar 25, 2002 | 2.1 | 11 | NO | NO |
Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, cale | Dec 4, 2006 | 1.7 | 10 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Palm.
Media articles that mention a CVE ID that affects a product developed by Palm — matched by CVE ID, not by vendor name.