CVE-2014-2385
- EPSS 0.65%
- Veröffentlicht 22.07.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems...
CVE-2010-2308
- EPSS 0.08%
- Veröffentlicht 16.06.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in the filter driver (savonaccessfilter.sys) in Sophos Anti-Virus before 7.6.20 allows local users to gain privileges via crafted arguments to the NtQueryAttributesFile function.
- EPSS 6.64%
- Veröffentlicht 06.08.2009 01:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Sophos SAVScan 4.33.0 for Linux, and possibly other products and versions, allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via crafted files that hav...
CVE-2008-6903
- EPSS 4.33%
- Veröffentlicht 06.08.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus for Windows before 7.6.3, Anti-Virus for Windows NT/9x before 4.7.18, Anti-Virus for OS X before 4.9.18, Anti-Virus for Linux before 6.4.5, Anti-Virus for UNIX before 7.0.5, Anti-Virus for Unix and Netware before 4.37.0, Sophos EM L...
CVE-2008-5541
- EPSS 0.76%
- Veröffentlicht 12.12.2008 18:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus 4.33.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension...
CVE-2008-1737
- EPSS 0.06%
- Veröffentlicht 30.04.2008 00:10:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field ...
CVE-2007-4512
- EPSS 0.69%
- Veröffentlicht 10.09.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted...
CVE-2007-4577
- EPSS 5.36%
- Veröffentlicht 28.08.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
CVE-2007-4578
- EPSS 9.01%
- Veröffentlicht 28.08.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070...
- EPSS 14.76%
- Veröffentlicht 01.11.2006 15:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malforme...