Sophos
sophos
168 CVEs • 73 products
Products (73)
Click to collapseToggle
Products (73)
Click to collapse
CVEs (168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the OS via a malformed IO...Show more |
2Rarlab Sophos2Threat Detection Engine UnrarMay 13, 2026 Jun 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow c...Show more |
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342. |
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit t...Show more |
1Sophos 1Cyberoam Cr25ing Utm Firmware May 13, 2026 Apr 7, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6...Show more |
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. |
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. |
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314. |
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304. |
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticToo...Show more |
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrRepor...Show more |
1Sophos 1Unified Threat Management Software May 6, 2026 Oct 3, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / sc...Show more |
1Sophos 1Unified Threat Management Software May 6, 2026 Oct 3, 2016 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications conf...Show more |
1Sophos 1Mobile Control Eas Proxy May 6, 2026 Aug 10, 2016 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open...Show more |
1Sophos 2Cyberoam Cr100ing Utm Firmware Cyberoam Cr35ing Utm FirmwareMay 6, 2026 Apr 6, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with...Show more |
10Canonical DebianF5+7 more30Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+27 moreMay 6, 2026 Feb 18, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash...Show more |
1Sophos 1Unified Threat Management Software May 6, 2026 Feb 17, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. |
5Apple HpOpenbsd+2 more6Linux Mac Os XOpenssh+3 moreMay 29, 2026 Jan 14, 2016 N/A· v4 8.1 HIGH· v3 4.6 MEDIUM· v2 The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection fi...Show more |
5Apple HpOpenbsd+2 more6Linux Mac Os XOpenssh+3 moreMay 29, 2026 Jan 14, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buff...Show more |
4Canonical DebianIsc+1 more4Debian Linux DhcpUbuntu Linux+1 moreMay 6, 2026 Jan 14, 2016 N/A· v4 6.5 MEDIUM· v3 5.7 MEDIUM· v2 ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. |