Show filters
163 Total Results
Displaying 41-50 of 163
Sort by:
Attacker Value
Unknown

CVE-2021-25270

Disclosure Date: October 08, 2021 (last updated November 28, 2024)
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
Attacker Value
Unknown

CVE-2021-25273

Disclosure Date: July 29, 2021 (last updated February 23, 2025)
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
Attacker Value
Unknown

CVE-2021-25264

Disclosure Date: May 17, 2021 (last updated November 28, 2024)
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
Attacker Value
Unknown

CVE-2021-25265

Disclosure Date: March 22, 2021 (last updated November 28, 2024)
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
Attacker Value
Unknown

CVE-2020-17352

Disclosure Date: August 07, 2020 (last updated February 21, 2025)
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2020-15504

Disclosure Date: July 10, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.
Attacker Value
Unknown

CVE-2020-15069

Disclosure Date: June 29, 2020 (last updated February 21, 2025)
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
Attacker Value
Unknown

CVE-2020-14980

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
Attacker Value
Unknown

CVE-2020-11503

Disclosure Date: June 18, 2020 (last updated February 21, 2025)
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
Attacker Value
Unknown

CVE-2020-10947

Disclosure Date: April 17, 2020 (last updated February 21, 2025)
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.