Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2023-44487

Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Attacker Value
Unknown

CVE-2014-2850

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
0
Attacker Value
Unknown

CVE-2014-2849

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
0
Attacker Value
Unknown

CVE-2013-4984

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
0
Attacker Value
Unknown

CVE-2013-4983

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.
0
Attacker Value
Unknown

CVE-2007-3699

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
0
Attacker Value
Unknown

CVE-2007-0447

Disclosure Date: October 05, 2007 (last updated October 04, 2023)
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
0