Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2023-33335
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
Iview
Mitigation only
MEDIUM 6.0
CVE-2021-36809
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial o…
Ssl Vpn Client
Mitigation only
CRITICAL 9.8
CVE-2020-12271 KEVEPSS 42%
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April…
Sfos
Mitigation only
HIGH 8.8
CVE-2018-16116
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute ar…
Sfos
Mitigation only
HIGH 7.8
CVE-2018-3971
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially craf…
Hitmanpro.alert
No fix yet
MEDIUM 5.5
CVE-2018-3970
An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially cr…
Hitmanpro.alert
No fix yet
HIGH 7.8
CVE-2016-8732
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver…
Invincea Dell Protected Workspace
No fix yet
HIGH 7.8
CVE-2016-9038
An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer …
Invincea X
No fix yet
HIGH 7.8
CVE-2018-9233
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which …
Endpoint Protection
No fix yet
MEDIUM 5.5
CVE-2018-4863
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\Curren…
Endpoint Protection
No fix yet
HIGH 7.8
CVE-2018-6318
In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payloa…
Sophos Tester
Mitigation only
MEDIUM 5.5
CVE-2018-6319
In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory addr…
Sophos Tester
Mitigation only
CRITICAL 9.8
CVE-2017-6315EPSS 17%
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
Astaro Security Gateway Firmware
No fix yet
HIGH 8.8
CVE-2016-7786EPSS 7%
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demo…
Cyberoam Cr25ing Utm Firmware
No fix yet
HIGH 7.2
CVE-2016-9553EPSS 19%
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. …
Web Appliance
No fix yet
HIGH 7.2
CVE-2016-9554EPSS 25%
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad…
Web Appliance
No fix yet
MEDIUM 6.1
CVE-2016-3968
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM applia…
Cyberoam Cr100ing Utm Firmware
No fix yet
HIGH 10.0
CVE-2013-5932EPSS 5%
Unspecified vulnerability in WebAdmin in Sophos UTM (aka Astaro Security Gateway) before 9.105 has unknown impact and attack vectors.
Unified Threat Management Software
No fix yet
MEDIUM 6.9
CVE-2010-5249
Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privile…
Free Encryption
Mitigation only
MEDIUM 6.2
CVE-2010-5177
Race condition in Sophos Endpoint Security and Control 9.0.5 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute danger…
Sophos Endpoint Security And Control
Mitigation only
HIGH 10.0
CVE-2008-6904EPSS 11%
Multiple unspecified vulnerabilities in Sophos SAVScan 4.33.0 for Linux, and possibly other products and versions, allow remote attackers to cause a …
Anti Virus
Mitigation only
HIGH 9.3
CVE-2008-5541EPSS 8%
Sophos Anti-Virus 4.33.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placin…
Anti Virus
Mitigation only
MEDIUM 5.0
CVE-2008-3177EPSS 5%
Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI…
Es1000
Mitigation only
MEDIUM 6.9
CVE-2008-1737
Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboo…
Anti Virus
Mitigation only
MEDIUM 5.0
CVE-2005-3382
Multiple interpretation error in Sophos 3.91 with the 2.28.4 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, an…
Sophos Anti Virus
Mitigation only
MEDIUM 5.1
CVE-2005-3216
Multiple interpretation error in unspecified versions of Sophos Antivirus allows remote attackers to bypass virus detection via a malicious executabl…
Sophos Anti Virus
No fix yet
HIGH 7.5
CVE-2005-2768EPSS 13%
Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote …
Sophos Anti Virus
Mitigation only
MEDIUM 5.1
CVE-2005-1551
Sophos Anti-Virus 3.93 does not check downloaded files for viruses when they have only been written, which creates a race condition and may allow rem…
Sophos Anti Virus
Mitigation only