Show filters
163 Total Results
Displaying 91-100 of 163
Sort by:
Attacker Value
Unknown
CVE-2016-3968
Disclosure Date: April 06, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.
0
Attacker Value
Unknown
CVE-2016-2046
Disclosure Date: February 17, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
0
Attacker Value
Unknown
CVE-2016-0777
Disclosure Date: January 14, 2016 (last updated November 25, 2024)
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
0
Attacker Value
Unknown
CVE-2015-8605
Disclosure Date: January 14, 2016 (last updated November 25, 2024)
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.
0
Attacker Value
Unknown
CVE-2016-0778
Disclosure Date: January 14, 2016 (last updated November 25, 2024)
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by requesting many forwardings.
0
Attacker Value
Unknown
CVE-2014-2385
Disclosure Date: July 22, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.
0
Attacker Value
Unknown
CVE-2014-2005
Disclosure Date: June 25, 2014 (last updated November 25, 2024)
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.
0
Attacker Value
Unknown
CVE-2014-2850
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
0
Attacker Value
Unknown
CVE-2014-2849
Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
0
Attacker Value
Unknown
CVE-2014-2537
Disclosure Date: March 18, 2014 (last updated October 05, 2023)
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
0