📦

sophos_puremessage_anti-virus

Vendor: sophos

Actively Exploited 0 CISA KEV List
PoC / Exploits 7 Code Available
Total RCEs 0 Remote Access
Total CVEs 18 Total Indexed
Avg. EPSS 19.40% Exploit Prob.
Latest CVE CVE-2008-3177 Jul 15

Security Vulnerability Index

Page 1 / 2
5.0 CVSS

Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.

EPSS: 5.13%
5.0 CVSS

Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.

EPSS: 6.16%
7.5 CVSS
CVE-2004-0937
Exploit Found

Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%
7.5 CVSS
CVE-2004-0934
Exploit Found

Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%
7.5 CVSS
CVE-2004-0936
Exploit Found

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 14.79%
7.5 CVSS
CVE-2004-0935
Exploit Found

Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 15.06%
7.5 CVSS
CVE-2004-0932
Exploit Found

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 65.76%
7.5 CVSS
CVE-2004-0933
Exploit Found

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 20.69%
7.5 CVSS
CVE-2004-1096
Exploit Found

Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.

EPSS: 17.44%