CVE-2014-1213
- EPSS 0.05%
- Veröffentlicht 10.02.2014 23:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protecti...
- EPSS 1.93%
- Veröffentlicht 10.09.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
CVE-2007-4577
- EPSS 5.36%
- Veröffentlicht 28.08.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
CVE-2007-4578
- EPSS 9.01%
- Veröffentlicht 28.08.2007 18:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070...