Sophos Scanning Engine vulnerabilities

4 known vulnerabilities affecting sophos/scanning_engine.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2014-1213MEDIUMCVSS 5.6≤ 3.482014-02-10
CVE-2014-1213 [MEDIUM] CWE-264 CVE-2014-1213: Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x befor Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof "rea
nvd
CVE-2007-4787MEDIUMCVSS 5.0v2.30.42007-09-10
CVE-2007-4787 [MEDIUM] CWE-20 CVE-2007-4787: The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1 The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
nvd
CVE-2007-4577HIGHCVSS 7.8v2.30.4v2.40.22007-08-28
CVE-2007-4577 [HIGH] CWE-399 CVE-2007-4577: Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
nvd
CVE-2007-4578MEDIUMCVSS 6.8v2.30.4v2.40.22007-08-28
CVE-2007-4578 [MEDIUM] CWE-189 CVE-2007-4578: Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a de Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researche
nvd