Skip to content
Noroxi

sophos records

170 published records for vendor sophos.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

170 records
  • A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    sophos · web applianceApr 4, 2023

  • An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    sophos · sfosMar 25, 2022

  • A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sophos · firewallSep 23, 2022

  • A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    sophos · unified threat managementSep 25, 2020

  • A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild

    CriticalCVSS 9.8KEVWeaponizedEPSS 42%

    sophos · sfosApr 27, 2020

  • CVE-2020-15069
    72This week

    Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles

    CriticalCVSS 9.8KEVWeaponizedEPSS 11%

    sophos · xg firewall firmwareJun 29, 2020

  • CVE-2020-29574
    70This week

    An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL s

    CriticalCVSS 9.8KEVWeaponizedEPSS 5%

    sophos · cyberoamosDec 11, 2020

  • CVE-2013-4983
    67This week

    The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to

    CriticalCVSS 10.0WeaponizedEPSS 90%

    sophos · web appliance firmwareSep 10, 2013

  • Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc

    HighCVSS 8.1Proof of conceptEPSS 91%

    gnu · glibcFeb 18, 2016

  • The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin

    HighCVSS 8.5WeaponizedEPSS 60%

    sophos · web appliance firmwareApr 11, 2014

  • ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash

    MediumCVSS 6.5No exploitEPSS 83%

    isc · dhcpJan 14, 2016

  • The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitra

    HighCVSS 8.5WeaponizedEPSS 58%

    sophos · web appliance firmwareApr 11, 2014

  • McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac

    HighCVSS 7.5Proof of conceptEPSS 63%

    ca · etrust antivirusJan 27, 2005

  • A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attacker

    HighCVSS 8.8No exploitEPSS 44%

    sophos · sfosJun 20, 2019

  • The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.

    MediumCVSS 4.3No exploitEPSS 100%

    avg · avg anti-virusMar 21, 2012

  • The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8

    MediumCVSS 4.3No exploitEPSS 100%

    ahnlab · v3 internet securityMar 21, 2012

  • The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman

    MediumCVSS 4.3No exploitEPSS 100%

    ca · etrust vet antivirusMar 21, 2012

  • The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010

    MediumCVSS 4.3No exploitEPSS 100%

    cat · quick healMar 21, 2012

  • The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwas

    MediumCVSS 4.3No exploitEPSS 99%

    cat · quick healMar 21, 2012

  • The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Tre

    MediumCVSS 4.3No exploitEPSS 98%

    ca · etrust vet antivirusMar 21, 2012

  • The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E

    MediumCVSS 4.3No exploitEPSS 96%

    bitdefender · bitdefenderMar 21, 2012

  • The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec

    MediumCVSS 4.3No exploitEPSS 96%

    bitdefender · bitdefenderMar 21, 2012

  • The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant

    MediumCVSS 4.3No exploitEPSS 92%

    anti-virus · vba32Mar 21, 2012

  • The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit

    MediumCVSS 6.5Proof of conceptEPSS 63%

    sophos · unified threat management softwareJan 14, 2016

  • In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remo

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    sophos · web applianceMar 30, 2017