Skip to main content

Vendor archive

sophos CVEs

Beta · best-effort

167 CVEs tagged to vendor sophos24 Critical, 60 High, 78 Medium, 5 Low, 0 Unrated.

CVE-2016-6217

Published Jan 26, 2018

Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18014

Published Jan 12, 2018

An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability fou…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7441

Published Sep 13, 2017

In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0 might lead to kernel data lea…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6008

Published Sep 13, 2017

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6007

Published Sep 13, 2017

A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9834

Published Jun 7, 2017

An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6184

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token para…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6183

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote comma…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6182

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9554

Published Jan 28, 2017

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9553

Published Jan 28, 2017

The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7442

Published Oct 3, 2016

The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the pro…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7397

Published Oct 3, 2016

The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMT…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6597

Published Aug 10, 2016

Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2046

Published Feb 17, 2016

Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0777

Published Jan 14, 2016

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Showing 76-100 of 167 CVEsPage 4 of 7