VendorsSophosscanning_engine2.30.4
Vulnerabilities

Sophos Scanning Engine 2.30.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2007-4577
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
Published 2007-08-28 · Modified
7.8EPSS 0.055
CVE-2007-4578
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows code execution, but the researcher is reliable.
Published 2007-08-28 · Modified
6.8EPSS 0.073
CVE-2007-4787
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
Published 2007-09-10 · Modified
5.0EPSS 0.057