VulnerabilityModified
CVE-2005-4680
Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.
MEDIUM 5.0EPSS 8.49%
Does this matter?
Lower severity and a low EPSS score (8.49%). Track it; it rarely justifies an emergency change on its own.
Description
Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 8.49% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- sophos/sophos anti-virus
- Source
- cve@mitre.org
References
- http://www.sophos.com/support/knowledgebase/article/3803.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2006/0347Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24345Third Party Advisory, VDB Entry
- http://www.sophos.com/support/knowledgebase/article/3803.htmlVendor Advisory
- http://www.vupen.com/english/advisories/2006/0347Permissions Required, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24345Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.