sophos

173 tracked vulnerabilities.

CVE-2018-6319 MEDIUM
Sophos Tester Tool 3.2.0.7 Beta - Denial of Service via DeviceIoControl NULL Pointer Dereference
Feb 02, 2018
CVSS 5.5
EPSS 0.00
CVE-2018-6318 HIGH
Sophos Tester Tool 3.2.0.7 Beta - Untrusted Search Path via DLL Hijacking
Feb 02, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-17023 HIGH
NCP Secure Entry Client 10.11 r32792 - Unauthenticated Arbitrary Code Execution via Insecure Update Metadata
Apr 09, 2019
CVSS 8.1
EPSS 0.00
CVE-2017-18014 MEDIUM
Sophos SFOS < 17.0.3 MR3 - Unauthenticated Stored Cross-Site Scripting via WAF Log User-Agent Parameter
Jan 12, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-6315 CRITICAL
Astaro Security Gateway 7 - Remote Code Execution via index.plx Request
Sep 19, 2017
CVSS 9.8
EPSS 0.09
CVE-2017-7441 HIGH
Sophos SurfRight HitmanPro <3.7.20 Build 286 - Info Disclosure
Sep 13, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-6008 HIGH
Sophos HitmanPro < 3.7.20 - Local Privilege Escalation via Malformed IOCTL Call
Sep 13, 2017
CVSS 7.8
EPSS 0.03
CVE-2017-6007 MEDIUM
Sophos HitmanPro < 3.7.20 - Kernel Pool Overflow via IOCTL Call
Sep 13, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-9523 MEDIUM
Sophos Web Appliance < 4.3.2 - Cross-Site Scripting in FTP Redirect Page
Jun 09, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-6412 HIGH
Sophos Web Appliance <4.3.1.2 - Session Fixation
Mar 30, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-6184 MEDIUM
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Report Token Parameter
Mar 30, 2017
CVSS 4.7
EPSS 0.01
CVE-2017-6183 HIGH
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Active Directory Configuration Utility
Mar 30, 2017
CVSS 7.2
EPSS 0.03
CVE-2017-6182 CRITICAL
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Report Generation Functions
Mar 30, 2017
CVSS 9.8
EPSS 0.15
CVE-2016-9038 HIGH
Invincea-X <6.1.3-24058 - Privilege Escalation
Apr 24, 2018
CVSS 7.8
EPSS 0.00
CVE-2016-8732 HIGH
Invincea Dell Protected Workspace <5.1.1-22303 - Privilege Escalation
Apr 24, 2018
CVSS 7.8
EPSS 0.00
CVE-2016-6217 MEDIUM
Sophos PureMessage for UNIX <6.3.2 - XSS
Jan 26, 2018
CVSS 6.1
EPSS 0.00
CVE-2016-9834 MEDIUM
Sophos Cyberoam Firewall Firmware <= 10.6.4 - Stored Cross-Site Scripting via LiveConnectionDetail.jsp Parameters
Jun 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-7786 HIGH
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 - Authenticated Direct Object Reference
Apr 07, 2017
CVSS 8.8
EPSS 0.03
CVE-2016-9554 HIGH
Sophos Web Appliance 4.2.1.3 - Remote Command Injection via MgrDiagnosticTools.php URL Parameter
Jan 28, 2017
CVSS 7.2
EPSS 0.11
CVE-2016-9553 HIGH
Sophos Web Appliance 4.2.1.3 - Authenticated Remote Command Injection via MgrReport.php
Jan 28, 2017
CVSS 7.2
EPSS 0.07
CVE-2016-7442 MEDIUM
Sophos Unified Threat Management Software <= 9.405-5 - Exposure of Sensitive Information via Proxy User Settings
Oct 03, 2016
CVSS 4.4
EPSS 0.00
CVE-2016-7397 MEDIUM
Sophos Unified Threat Management Software <= 9.405-5 - Sensitive Password Information Exposure via SMTP User Settings
Oct 03, 2016
CVSS 4.4
EPSS 0.00
CVE-2016-6597 HIGH
Sophos Mobile Control EAS Proxy < 3.5.0.3 - Open Reverse Proxy via Lotus Traveler
Aug 10, 2016
CVSS 8.6
EPSS 0.00
CVE-2016-3968 MEDIUM
Sophos Cyberoam CR100iNG UTM <10.6.3 MR-1 build 503 - XSS
Apr 06, 2016
CVSS 6.1
EPSS 0.00
CVE-2016-2046 MEDIUM
Sophos Unified Threat Management Software < 9.351 - Cross-Site Scripting via UserPortal Lang Parameter
Feb 17, 2016
CVSS 6.1
EPSS 0.01