Synchro operates a bulletin board system (BBS) product with a narrow but historically significant footprint in dial-up and early internet connectivity services. The observed vulnerability pattern centers on resource-initialization weaknesses and incomplete information artifacts, typical of legacy software with limited ongoing maintenance visibility. Current severity, exploitation status, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Synchro over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6371HIGH Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header. | Feb 27, 2020 | 7.5 | 30 | NO | YES |
CVE-2021-36512HIGH An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers to view sensitive information due to an uninitialized value. | Oct 19, 2021 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Synchro.
Media articles that mention a CVE ID that affects a product developed by Synchro — matched by CVE ID, not by vendor name.