Vulnerability index

Browse CVEs

124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2018-6856 Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca… Safeguard Easy Device Encryption Client Patch available Fix from $1,9502018-07-09 HIGH 7.8 CVE-2016-8732 Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver… Invincea Dell Protected Workspace No fix yet Fix from $1,9502018-04-24 HIGH 7.8 CVE-2016-9038 An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer … Invincea X No fix yet Fix from $1,9502018-04-24 HIGH 7.8 CVE-2018-9233 Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which … Endpoint Protection No fix yet Fix from $1,9502018-04-05 MEDIUM 5.5 CVE-2018-4863 Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\Curren… Endpoint Protection No fix yet Fix from $1,6002018-04-05 HIGH 7.8 CVE-2018-6318 In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payloa… Sophos Tester Mitigation only Fix from $1,9502018-02-02 MEDIUM 5.5 CVE-2018-6319 In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory addr… Sophos Tester Mitigation only Fix from $1,6002018-02-02 MEDIUM 6.1 CVE-2016-6217 Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML v… Puremessage 6.3.2+ Fix from $1,6002018-01-26 MEDIUM 6.1 CVE-2017-18014 An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a pe… Sfos after 17.0 Fix from $1,6002018-01-12 CRITICAL 9.8 CVE-2017-6315EPSS 17% Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx. Astaro Security Gateway Firmware No fix yet Fix from $2,3002017-09-19 HIGH 7.8 CVE-2017-6008 A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution … Hitmanpro after 3.7.20 Fix from $1,9502017-09-13 HIGH 7.8 CVE-2017-7441 In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0… Hitmanpro after 3.7.20 Fix from $1,9502017-09-13 MEDIUM 5.5 CVE-2017-6007 A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution … Hitmanpro after 3.7.20 Fix from $1,6002017-09-13 CRITICAL 9.8 CVE-2012-6706EPSS 10% A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other pro… Threat Detection Engine after 5.5.4 Fix from $2,3002017-06-22 MEDIUM 6.1 CVE-2017-9523 The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342. Web Appliance after 4.3.1.4 Fix from $1,6002017-06-09 MEDIUM 6.1 CVE-2016-9834 An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices … Cyberoam Firmware after 10.6.4 Fix from $1,6002017-06-07 HIGH 8.8 CVE-2016-7786EPSS 7% Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demo… Cyberoam Cr25ing Utm Firmware No fix yet Fix from $1,9502017-04-07 CRITICAL 9.8 CVE-2017-6182EPSS 17% In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman… Web Appliance after 4.3.1.1 Fix from $2,3002017-03-30 HIGH 8.1 CVE-2017-6412EPSS 8% In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. Web Appliance after 4.3.1.1 Fix from $1,9502017-03-30 HIGH 7.2 CVE-2017-6183 In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers … Web Appliance after 4.3.1.1 Fix from $1,9502017-03-30 HIGH 7.2 CVE-2016-9553EPSS 19% The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. … Web Appliance No fix yet Fix from $1,9502017-01-28 HIGH 7.2 CVE-2016-9554EPSS 25% The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad… Web Appliance No fix yet Fix from $1,9502017-01-28 HIGH 8.6 CVE-2016-6597 Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources fr… Mobile Control Eas Proxy after 3.5.0.3 Fix from $1,9502016-08-10 MEDIUM 6.1 CVE-2016-3968 Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM applia… Cyberoam Cr100ing Utm Firmware No fix yet Fix from $1,6002016-04-06 MEDIUM 6.1 CVE-2016-2046 Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or … Unified Threat Management Software after 9.351 Fix from $1,6002016-02-17 MEDIUM 6.8 CVE-2014-2005 Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu… Enterprise Console after 5.2.1 Fix from $1,6002014-06-25 HIGH 8.5 CVE-2014-2849EPSS 60% The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass… Web Appliance Firmware after 3.8.1.1 Fix from $1,9502014-04-11 HIGH 8.5 CVE-2014-2850EPSS 58% The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary comman… Web Appliance Firmware after 3.8.1.1 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2537 Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via u… Unified Threat Management Software after 9.108 Fix from $1,9502014-03-18 HIGH 9.3 CVE-2013-2642EPSS 7% Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to … Web Appliance Firmware after 3.7.8.1 Fix from $1,9502014-03-18