Show filters
163 Total Results
Displaying 11-20 of 163
Sort by:
Attacker Value
Unknown

CVE-2024-8885

Disclosure Date: October 02, 2024 (last updated October 03, 2024)
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.
0
Attacker Value
Unknown

CVE-2021-36806

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.
Attacker Value
Unknown

CVE-2023-5552

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
Attacker Value
Unknown

CVE-2023-33335

Disclosure Date: July 05, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
Attacker Value
Unknown

CVE-2023-33336

Disclosure Date: June 30, 2023 (last updated October 08, 2023)
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
Attacker Value
Unknown

CVE-2023-1671

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Attacker Value
Unknown

CVE-2022-4934

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
Attacker Value
Unknown

CVE-2020-36692

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
Attacker Value
Unknown

CVE-2022-4901

Disclosure Date: March 01, 2023 (last updated October 08, 2023)
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
Attacker Value
Unknown

CVE-2022-48310

Disclosure Date: March 01, 2023 (last updated October 08, 2023)
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.