Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2018-6856
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2016-8732
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver…
Invincea Dell Protected Workspace
No fix yet
HIGH 7.8
CVE-2016-9038
An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer …
Invincea X
No fix yet
HIGH 7.8
CVE-2018-9233
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which …
Endpoint Protection
No fix yet
MEDIUM 5.5
CVE-2018-4863
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\Curren…
Endpoint Protection
No fix yet
HIGH 7.8
CVE-2018-6318
In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payloa…
Sophos Tester
Mitigation only
MEDIUM 5.5
CVE-2018-6319
In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory addr…
Sophos Tester
Mitigation only
MEDIUM 6.1
CVE-2016-6217
Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML v…
Puremessage
6.3.2+
MEDIUM 6.1
CVE-2017-18014
An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a pe…
Sfos
after 17.0
CRITICAL 9.8
CVE-2017-6315EPSS 17%
Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.
Astaro Security Gateway Firmware
No fix yet
HIGH 7.8
CVE-2017-6008
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution …
Hitmanpro
after 3.7.20
HIGH 7.8
CVE-2017-7441
In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0…
Hitmanpro
after 3.7.20
MEDIUM 5.5
CVE-2017-6007
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution …
Hitmanpro
after 3.7.20
CRITICAL 9.8
CVE-2012-6706EPSS 10%
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other pro…
Threat Detection Engine
after 5.5.4
MEDIUM 6.1
CVE-2017-9523
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.
Web Appliance
after 4.3.1.4
MEDIUM 6.1
CVE-2016-9834
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices …
Cyberoam Firmware
after 10.6.4
HIGH 8.8
CVE-2016-7786EPSS 7%
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demo…
Cyberoam Cr25ing Utm Firmware
No fix yet
CRITICAL 9.8
CVE-2017-6182EPSS 17%
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…
Web Appliance
after 4.3.1.1
HIGH 8.1
CVE-2017-6412EPSS 8%
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
Web Appliance
after 4.3.1.1
HIGH 7.2
CVE-2017-6183
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …
Web Appliance
after 4.3.1.1
HIGH 7.2
CVE-2016-9553EPSS 19%
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. …
Web Appliance
No fix yet
HIGH 7.2
CVE-2016-9554EPSS 25%
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web ad…
Web Appliance
No fix yet
HIGH 8.6
CVE-2016-6597
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources fr…
Mobile Control Eas Proxy
after 3.5.0.3
MEDIUM 6.1
CVE-2016-3968
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM applia…
Cyberoam Cr100ing Utm Firmware
No fix yet
MEDIUM 6.1
CVE-2016-2046
Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or …
Unified Threat Management Software
after 9.351
MEDIUM 6.8
CVE-2014-2005
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resu…
Enterprise Console
after 5.2.1
HIGH 8.5
CVE-2014-2849EPSS 60%
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass…
Web Appliance Firmware
after 3.8.1.1
HIGH 8.5
CVE-2014-2850EPSS 58%
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary comman…
Web Appliance Firmware
after 3.8.1.1
HIGH 7.8
CVE-2014-2537
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via u…
Unified Threat Management Software
after 9.108
HIGH 9.3
CVE-2013-2642EPSS 7%
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …
Web Appliance Firmware
after 3.7.8.1