Skip to main content

Vendor archive

sophos CVEs

Beta · best-effort

167 CVEs tagged to vendor sophos24 Critical, 60 High, 78 Medium, 5 Low, 0 Unrated.

CVE-2020-11503

Published Jun 18, 2020

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12271

Published Apr 27, 2020

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices c…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
57.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-9540

Published Mar 2, 2020

Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17059

Published Oct 11, 2019

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admi…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2018-16118

Published Jun 20, 2019

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS comm…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16117

Published Jun 20, 2019

A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16116

Published Jun 20, 2019

SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3971

Published Oct 25, 2018

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-3970

Published Oct 25, 2018

An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause th…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9038

Published Apr 24, 2018

An exploitable double fetch vulnerability exists in the SboxDrv.sys driver functionality of Invincea-X 6.1.3-24058. A specially crafted input buffer and race condition can result…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-8732

Published Apr 24, 2018

Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and add…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2018-9233

Published Apr 5, 2018

Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4863

Published Apr 5, 2018

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos En…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6319

Published Feb 2, 2018

In Sophos Tester Tool 3.2.0.7 Beta, the driver accepts a special DeviceIoControl code that doesn't check its argument. This argument is a memory address: if a caller passes a NULL…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6318

Published Feb 2, 2018

In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payload that runs from NTDLL.DLL (so…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 167 CVEsPage 3 of 7