Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2010-2308
Disclosure Date: June 16, 2010 (last updated October 04, 2023)
Unspecified vulnerability in the filter driver (savonaccessfilter.sys) in Sophos Anti-Virus before 7.6.20 allows local users to gain privileges via crafted arguments to the NtQueryAttributesFile function.
0
Attacker Value
Unknown
CVE-2007-4787
Disclosure Date: September 10, 2007 (last updated October 04, 2023)
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
0
Attacker Value
Unknown
CVE-2007-4578
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.
0
Attacker Value
Unknown
CVE-2007-4577
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
0
Attacker Value
Unknown
CVE-2006-5646
Disclosure Date: November 01, 2006 (last updated October 04, 2023)
Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that specifies a Window_size of 0.
0
Attacker Value
Unknown
CVE-2006-5647
Disclosure Date: November 01, 2006 (last updated October 04, 2023)
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."
0
Attacker Value
Unknown
CVE-2006-5645
Disclosure Date: November 01, 2006 (last updated October 04, 2023)
Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.
0
Attacker Value
Unknown
CVE-2005-2768
Disclosure Date: September 02, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length.
0
Attacker Value
Unknown
CVE-2005-1530
Disclosure Date: July 19, 2005 (last updated February 22, 2025)
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.
0