VendorsFlexensediskbossall versions
Vulnerabilities

Flexense DiskBoss

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2018-5262
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the context of a highly privileged account.
Published 2018-01-12 · Modified
10.01 PoCEPSS 0.391
CVE-2020-36882
Flexsense DiskBoss Application Crash Denial of Service
Published 2025-12-05 · Analyzed
8.7EPSS 0.006
CVE-2020-36881
Flexsense DiskBoss 'Add Input Directory' Buffer Overflow
Published 2025-12-05 · Analyzed
8.6EPSS 0.004
CVE-2020-36880
Flexsense DiskBoss 'Reports and Data Directory' Buffer Overflow
Published 2025-12-05 · Analyzed
8.6EPSS 0.002
CVE-2018-5261
An issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryption key used for the encryption of the rest of the session, the server and client disclose sensitive information, such as the authentication credentials, to any man-in-the-middle (MiTM) listener.
Published 2018-02-02 · Modified
8.1EPSS 0.005
CVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.
Published 2017-03-29 · Modified
7.83 PoCEPSS 0.537
CVE-2017-15665
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
Published 2018-01-10 · Modified
7.51 PoCEPSS 0.091
CVE-2018-10294
Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.
Published 2018-05-02 · Modified
6.1EPSS 0.007