Vulnerability index

Browse CVEs

124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6856

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Invincea Dell Protected Workspace HIGH 7.8
CVE-2016-8732

Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver…

No fix yet
Fix from $1,950 2018-04-24
Invincea X HIGH 7.8
CVE-2016-9038

An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer …

No fix yet
Fix from $1,950 2018-04-24
Endpoint Protection HIGH 7.8
CVE-2018-9233

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which …

No fix yet
Fix from $1,950 2018-04-05
Endpoint Protection MEDIUM 5.5
CVE-2018-4863

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\Curren…

No fix yet
Fix from $1,600 2018-04-05
Sophos Tester HIGH 7.8
CVE-2018-6318

In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payloa…

Mitigation only
Fix from $1,950 2018-02-02
Sophos Tester MEDIUM 5.5
CVE-2018-6319

In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory addr…

Mitigation only
Fix from $1,600 2018-02-02
Puremessage MEDIUM 6.1
CVE-2016-6217

Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML v…

Fix: 6.3.2+
Fix from $1,600 2018-01-26
Sfos MEDIUM 6.1
CVE-2017-18014

An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a pe…

Fix: after 17.0
Fix from $1,600 2018-01-12
Astaro Security Gateway Firmware CRITICAL 9.8
CVE-2017-6315EPSS 17%

Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.

No fix yet
Fix from $2,300 2017-09-19
Hitmanpro HIGH 7.8
CVE-2017-6008

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution …

Fix: after 3.7.20
Fix from $1,950 2017-09-13
Hitmanpro HIGH 7.8
CVE-2017-7441

In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0…

Fix: after 3.7.20
Fix from $1,950 2017-09-13
Hitmanpro MEDIUM 5.5
CVE-2017-6007

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution …

Fix: after 3.7.20
Fix from $1,600 2017-09-13
Threat Detection Engine CRITICAL 9.8
CVE-2012-6706EPSS 10%

A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other pro…

Fix: after 5.5.4
Fix from $2,300 2017-06-22
Web Appliance MEDIUM 6.1
CVE-2017-9523

The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.

Fix: after 4.3.1.4
Fix from $1,600 2017-06-09
Cyberoam Firmware MEDIUM 6.1
CVE-2016-9834

An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices …

Fix: after 10.6.4
Fix from $1,600 2017-06-07
Cyberoam Cr25ing Utm Firmware HIGH 8.8
CVE-2016-7786EPSS 7%

Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demo…

No fix yet
Fix from $1,950 2017-04-07
Web Appliance CRITICAL 9.8
CVE-2017-6182EPSS 17%

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…

Fix: after 4.3.1.1
Fix from $2,300 2017-03-30
Web Appliance HIGH 8.1
CVE-2017-6412EPSS 8%

In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.

Fix: after 4.3.1.1
Fix from $1,950 2017-03-30
Web Appliance HIGH 7.2
CVE-2017-6183

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …

Fix: after 4.3.1.1
Fix from $1,950 2017-03-30
Web Appliance HIGH 7.2
CVE-2016-9553EPSS 19%

The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. …

No fix yet
Fix from $1,950 2017-01-28
Web Appliance HIGH 7.2
CVE-2016-9554EPSS 25%

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad…

No fix yet
Fix from $1,950 2017-01-28
Mobile Control Eas Proxy HIGH 8.6
CVE-2016-6597

Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources fr…

Fix: after 3.5.0.3
Fix from $1,950 2016-08-10
Cyberoam Cr100ing Utm Firmware MEDIUM 6.1
CVE-2016-3968

Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM applia…

No fix yet
Fix from $1,600 2016-04-06
Unified Threat Management Software MEDIUM 6.1
CVE-2016-2046

Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or …

Fix: after 9.351
Fix from $1,600 2016-02-17
Enterprise Console MEDIUM 6.8
CVE-2014-2005

Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu…

Fix: after 5.2.1
Fix from $1,600 2014-06-25
Web Appliance Firmware HIGH 8.5
CVE-2014-2849EPSS 60%

The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass…

Fix: after 3.8.1.1
Fix from $1,950 2014-04-11
Web Appliance Firmware HIGH 8.5
CVE-2014-2850EPSS 58%

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary comman…

Fix: after 3.8.1.1
Fix from $1,950 2014-04-11
Unified Threat Management Software HIGH 7.8
CVE-2014-2537

Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via u…

Fix: after 9.108
Fix from $1,950 2014-03-18
Web Appliance Firmware HIGH 9.3
CVE-2013-2642EPSS 7%

Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …

Fix: after 3.7.8.1
Fix from $1,950 2014-03-18