VYPR

Unified Threat Management Software

by Sophos

CVEs (15)

  • CVE-2020-25223CriKEVSep 25, 2020
    risk 0.86cvss 9.8epss 0.97

    A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

  • CVE-2015-7547HigFeb 18, 2016
    risk 0.63cvss 8.1epss 0.90

    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS…

  • CVE-2022-0386HigMar 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.

  • CVE-2021-36807HigNov 26, 2021
    risk 0.57cvss 8.8epss 0.01

    An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

  • CVE-2016-0778HigJan 14, 2016
    risk 0.54cvss 8.1epss 0.21

    The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows remote servers to cause a…

  • CVE-2015-8605MedJan 14, 2016
    risk 0.48cvss 6.5epss 0.76

    ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet.

  • CVE-2016-0777MedJan 14, 2016
    risk 0.47cvss 6.5epss 0.63

    The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

  • CVE-2016-2046MedFeb 17, 2016
    risk 0.40cvss 6.1epss 0.03

    Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

  • CVE-2021-25273MedJul 29, 2021
    risk 0.31cvss 4.8epss 0.01

    Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.

  • CVE-2016-7442MedOct 3, 2016
    risk 0.29cvss 4.4epss 0.01

    The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.

  • CVE-2016-7397MedOct 3, 2016
    risk 0.29cvss 4.4epss 0.01

    The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.

  • CVE-2022-0652LowMar 22, 2022
    risk 0.21cvss 3.3epss 0.00

    Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.

  • CVE-2014-2537Mar 18, 2014
    risk 0.00cvss epss 0.03

    Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

  • CVE-2013-5932Sep 23, 2013
    risk 0.00cvss epss 0.05

    Unspecified vulnerability in WebAdmin in Sophos UTM (aka Astaro Security Gateway) before 9.105 has unknown impact and attack vectors.

  • CVE-2012-3238Jul 9, 2012
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.