sophos kayıtları
sophos üreticisine ait 170 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 7 · %4,1
- Silahlaştırılmış
- 12 · %7,1
- Pre-auth RCE
- 30
- Düzeltme kaydı olan
- %11,2
- Yayından KEV’e ortanca
- 546 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls19
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
170 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2023-1671Silahlaştırılmış | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Kritik9,8 | KEV | %100,0 | 4 Nis 2023 |
99Hemen | CVE-2022-1040Silahlaştırılmış | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version vsophos · sfos | Kritik9,8 | KEV | %99,8 | 25 Mar 2022 |
99Hemen | CVE-2022-3236Silahlaştırılmış | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Kritik9,8 | KEV | %98,9 | 23 Eyl 2022 |
98Hemen | CVE-2020-25223Silahlaştırılmış | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11sophos · unified threat management · CWE-78 | Kritik9,8 | KEV | %96,8 | 25 Eyl 2020 |
82Hemen | CVE-2020-12271Silahlaştırılmış | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wildsophos · sfos · CWE-89 | Kritik9,8 | KEV | %42,4 | 27 Nis 2020 |
72Bu hafta | CVE-2020-15069Silahlaştırılmış | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlessophos · xg firewall firmware · CWE-120 | Kritik9,8 | KEV | %10,7 | 29 Haz 2020 |
70Bu hafta | CVE-2020-29574Silahlaştırılmış | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL ssophos · cyberoamos · CWE-89 | Kritik9,8 | KEV | %4,7 | 11 Ara 2020 |
67Bu hafta | CVE-2013-4983Silahlaştırılmış | The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers tosophos · web appliance firmware · CWE-78 | Kritik10,0 | — | %90,1 | 10 Eyl 2013 |
59Planlayın | CVE-2015-7547Kavram kanıtı | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | Yüksek8,1 | — | %91,0 | 18 Şub 2016 |
52Planlayın | CVE-2014-2849Silahlaştırılmış | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin sophos · web appliance firmware · CWE-264 | Yüksek8,5 | — | %60,3 | 11 Nis 2014 |
51Planlayın | CVE-2015-8605İstismar yok | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Orta6,5 | — | %82,7 | 14 Oca 2016 |
51Planlayın | CVE-2014-2850Silahlaştırılmış | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrasophos · web appliance firmware · CWE-78 | Yüksek8,5 | — | %57,7 | 11 Nis 2014 |
49Planlayın | CVE-2004-0932Kavram kanıtı | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | Yüksek7,5 | — | %63,4 | 27 Oca 2005 |
48Planlayın | CVE-2018-16117İstismar yok | A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackersophos · sfos · CWE-78 | Yüksek8,8 | — | %44,3 | 20 Haz 2019 |
47Planlayın | CVE-2012-1456İstismar yok | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Orta4,3 | — | %99,9 | 21 Mar 2012 |
47Planlayın | CVE-2012-1459İstismar yok | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Orta4,3 | — | %99,8 | 21 Mar 2012 |
47Planlayın | CVE-2012-1446İstismar yok | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Orta4,3 | — | %99,7 | 21 Mar 2012 |
47Planlayın | CVE-2012-1443İstismar yok | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Orta4,3 | — | %99,6 | 21 Mar 2012 |
47Planlayın | CVE-2012-1442İstismar yok | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwascat · quick heal · CWE-264 | Orta4,3 | — | %98,9 | 21 Mar 2012 |
46Planlayın | CVE-2012-1453İstismar yok | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Treca · etrust vet antivirus · CWE-264 | Orta4,3 | — | %97,7 | 21 Mar 2012 |
46Planlayın | CVE-2012-1430İstismar yok | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Orta4,3 | — | %96,0 | 21 Mar 2012 |
46Planlayın | CVE-2012-1431İstismar yok | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Orta4,3 | — | %96,0 | 21 Mar 2012 |
45Planlayın | CVE-2012-1461İstismar yok | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Orta4,3 | — | %91,7 | 21 Mar 2012 |
45Planlayın | CVE-2016-0777Kavram kanıtı | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Orta6,5 | — | %63,5 | 14 Oca 2016 |
44Planlayın | CVE-2017-6182Kavram kanıtı | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remosophos · web appliance · CWE-78 | Kritik9,8 | — | %16,7 | 30 Mar 2017 |
- CVE-2023-167199Hemen
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100sophos · web appliance4 Nis 2023
- CVE-2022-104099Hemen
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100sophos · sfos25 Mar 2022
- CVE-2022-323699Hemen
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99sophos · firewall23 Eyl 2022
- CVE-2020-2522398Hemen
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97sophos · unified threat management25 Eyl 2020
- CVE-2020-1227182Hemen
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %42sophos · sfos27 Nis 2020
- CVE-2020-1506972Bu hafta
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %11sophos · xg firewall firmware29 Haz 2020
- CVE-2020-2957470Bu hafta
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL s
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %5sophos · cyberoamos11 Ara 2020
- CVE-2013-498367Bu hafta
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to
KritikCVSS 10,0SilahlaştırılmışEPSS %90sophos · web appliance firmware10 Eyl 2013
- CVE-2015-754759Planlayın
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
YüksekCVSS 8,1Kavram kanıtıEPSS %91gnu · glibc18 Şub 2016
- CVE-2014-284952Planlayın
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin
YüksekCVSS 8,5SilahlaştırılmışEPSS %60sophos · web appliance firmware11 Nis 2014
- CVE-2015-860551Planlayın
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
OrtaCVSS 6,5İstismar yokEPSS %83isc · dhcp14 Oca 2016
- CVE-2014-285051Planlayın
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitra
YüksekCVSS 8,5SilahlaştırılmışEPSS %58sophos · web appliance firmware11 Nis 2014
- CVE-2004-093249Planlayın
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
YüksekCVSS 7,5Kavram kanıtıEPSS %63ca · etrust antivirus27 Oca 2005
- CVE-2018-1611748Planlayın
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attacker
YüksekCVSS 8,8İstismar yokEPSS %44sophos · sfos20 Haz 2019
- CVE-2012-145647Planlayın
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
OrtaCVSS 4,3İstismar yokEPSS %100avg · avg anti-virus21 Mar 2012
- CVE-2012-145947Planlayın
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
OrtaCVSS 4,3İstismar yokEPSS %100ahnlab · v3 internet security21 Mar 2012
- CVE-2012-144647Planlayın
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
OrtaCVSS 4,3İstismar yokEPSS %100ca · etrust vet antivirus21 Mar 2012
- CVE-2012-144347Planlayın
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
OrtaCVSS 4,3İstismar yokEPSS %100cat · quick heal21 Mar 2012
- CVE-2012-144247Planlayın
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwas
OrtaCVSS 4,3İstismar yokEPSS %99cat · quick heal21 Mar 2012
- CVE-2012-145346Planlayın
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Tre
OrtaCVSS 4,3İstismar yokEPSS %98ca · etrust vet antivirus21 Mar 2012
- CVE-2012-143046Planlayın
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
OrtaCVSS 4,3İstismar yokEPSS %96bitdefender · bitdefender21 Mar 2012
- CVE-2012-143146Planlayın
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
OrtaCVSS 4,3İstismar yokEPSS %96bitdefender · bitdefender21 Mar 2012
- CVE-2012-146145Planlayın
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
OrtaCVSS 4,3İstismar yokEPSS %92anti-virus · vba3221 Mar 2012
- CVE-2016-077745Planlayın
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
OrtaCVSS 6,5Kavram kanıtıEPSS %63sophos · unified threat management software14 Oca 2016
- CVE-2017-618244Planlayın
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remo
KritikCVSS 9,8Kavram kanıtıEPSS %17sophos · web appliance30 Mar 2017