sophos
173 tracked vulnerabilities.
CVE-2018-6319
MEDIUM
Sophos Tester Tool 3.2.0.7 Beta - Denial of Service via DeviceIoControl NULL Pointer Dereference
Feb 02, 2018
CVSS 5.5
EPSS 0.00
CVE-2018-6318
HIGH
Sophos Tester Tool 3.2.0.7 Beta - Untrusted Search Path via DLL Hijacking
Feb 02, 2018
CVSS 7.8
EPSS 0.00
CVE-2017-17023
HIGH
NCP Secure Entry Client 10.11 r32792 - Unauthenticated Arbitrary Code Execution via Insecure Update Metadata
Apr 09, 2019
CVSS 8.1
EPSS 0.00
CVE-2017-18014
MEDIUM
Sophos SFOS < 17.0.3 MR3 - Unauthenticated Stored Cross-Site Scripting via WAF Log User-Agent Parameter
Jan 12, 2018
CVSS 6.1
EPSS 0.00
CVE-2017-6315
CRITICAL
Astaro Security Gateway 7 - Remote Code Execution via index.plx Request
Sep 19, 2017
CVSS 9.8
EPSS 0.09
CVE-2017-7441
HIGH
Sophos SurfRight HitmanPro <3.7.20 Build 286 - Info Disclosure
Sep 13, 2017
CVSS 7.8
EPSS 0.00
CVE-2017-6008
HIGH
Sophos HitmanPro < 3.7.20 - Local Privilege Escalation via Malformed IOCTL Call
Sep 13, 2017
CVSS 7.8
EPSS 0.03
CVE-2017-6007
MEDIUM
Sophos HitmanPro < 3.7.20 - Kernel Pool Overflow via IOCTL Call
Sep 13, 2017
CVSS 5.5
EPSS 0.00
CVE-2017-9523
MEDIUM
Sophos Web Appliance < 4.3.2 - Cross-Site Scripting in FTP Redirect Page
Jun 09, 2017
CVSS 6.1
EPSS 0.00
CVE-2017-6412
HIGH
Sophos Web Appliance <4.3.1.2 - Session Fixation
Mar 30, 2017
CVSS 8.1
EPSS 0.01
CVE-2017-6184
MEDIUM
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Report Token Parameter
Mar 30, 2017
CVSS 4.7
EPSS 0.01
CVE-2017-6183
HIGH
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Active Directory Configuration Utility
Mar 30, 2017
CVSS 7.2
EPSS 0.03
CVE-2017-6182
CRITICAL
Sophos Web Appliance < 4.3.1.2 - Remote Command Injection via Report Generation Functions
Mar 30, 2017
CVSS 9.8
EPSS 0.15
CVE-2016-9038
HIGH
Invincea-X <6.1.3-24058 - Privilege Escalation
Apr 24, 2018
CVSS 7.8
EPSS 0.00
CVE-2016-8732
HIGH
Invincea Dell Protected Workspace <5.1.1-22303 - Privilege Escalation
Apr 24, 2018
CVSS 7.8
EPSS 0.00
CVE-2016-6217
MEDIUM
Sophos PureMessage for UNIX <6.3.2 - XSS
Jan 26, 2018
CVSS 6.1
EPSS 0.00
CVE-2016-9834
MEDIUM
Sophos Cyberoam Firewall Firmware <= 10.6.4 - Stored Cross-Site Scripting via LiveConnectionDetail.jsp Parameters
Jun 07, 2017
CVSS 6.1
EPSS 0.00
CVE-2016-7786
HIGH
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 - Authenticated Direct Object Reference
Apr 07, 2017
CVSS 8.8
EPSS 0.03
CVE-2016-9554
HIGH
Sophos Web Appliance 4.2.1.3 - Remote Command Injection via MgrDiagnosticTools.php URL Parameter
Jan 28, 2017
CVSS 7.2
EPSS 0.11
CVE-2016-9553
HIGH
Sophos Web Appliance 4.2.1.3 - Authenticated Remote Command Injection via MgrReport.php
Jan 28, 2017
CVSS 7.2
EPSS 0.07
CVE-2016-7442
MEDIUM
Sophos Unified Threat Management Software <= 9.405-5 - Exposure of Sensitive Information via Proxy User Settings
Oct 03, 2016
CVSS 4.4
EPSS 0.00
CVE-2016-7397
MEDIUM
Sophos Unified Threat Management Software <= 9.405-5 - Sensitive Password Information Exposure via SMTP User Settings
Oct 03, 2016
CVSS 4.4
EPSS 0.00
CVE-2016-6597
HIGH
Sophos Mobile Control EAS Proxy < 3.5.0.3 - Open Reverse Proxy via Lotus Traveler
Aug 10, 2016
CVSS 8.6
EPSS 0.00
CVE-2016-3968
MEDIUM
Sophos Cyberoam CR100iNG UTM <10.6.3 MR-1 build 503 - XSS
Apr 06, 2016
CVSS 6.1
EPSS 0.00
CVE-2016-2046
MEDIUM
Sophos Unified Threat Management Software < 9.351 - Cross-Site Scripting via UserPortal Lang Parameter
Feb 17, 2016
CVSS 6.1
EPSS 0.01
Products
sophos_anti-virus 35
web_appliance 17
anti-virus 12
firewall_firmware 10
sophos_puremessage_anti-virus 9
unified_threat_management_software 9
xg_firewall_firmware 9
safeguard_easy_device_encryption_client 8
sfos 8
sophos_small_business_suite 8
safeguard_enterprise_client 7
safeguard_lan_crypt_client 7
unified_threat_management 6
web_appliance_firmware 6
connect 4
hitmanpro 4
hitmanpro.alert 4
scanning_engine 4
endpoint_protection 3
endpoint_security 3
firewall 3
puremessage_for_microsoft_exchange 3
small_business_suite 3
anti-virus7.6.3 2
cyberoamos 2
es1000 2
es4000 2
intercept_x 2
intercept_x_endpoint 2
intercept_x_for_server 2
Quick Filters