Show filters
163 Total Results
Displaying 11-20 of 163
Sort by:
Attacker Value
Unknown
CVE-2024-8885
Disclosure Date: October 02, 2024 (last updated October 03, 2024)
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.
0
Attacker Value
Unknown
CVE-2021-36806
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on
Sophos Email Appliance
older than version 4.5.3.4.
0
Attacker Value
Unknown
CVE-2023-5552
Disclosure Date: October 18, 2023 (last updated October 25, 2023)
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
0
Attacker Value
Unknown
CVE-2023-33335
Disclosure Date: July 05, 2023 (last updated October 08, 2023)
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
0
Attacker Value
Unknown
CVE-2023-33336
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
0
Attacker Value
Unknown
CVE-2023-1671
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
0
Attacker Value
Unknown
CVE-2022-4934
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2020-36692
Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
0
Attacker Value
Unknown
CVE-2022-4901
Disclosure Date: March 01, 2023 (last updated October 08, 2023)
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
0
Attacker Value
Unknown
CVE-2022-48310
Disclosure Date: March 01, 2023 (last updated October 08, 2023)
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
0