Vulnerabilities > Sophos > Sophos Anti Virus > 4.7.1

DATE CVE VULNERABILITY TITLE RISK
2007-09-10 CVE-2007-4787 Improper Input Validation vulnerability in Sophos Scanning Engine and Sophos Anti-Virus
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
network
low complexity
sophos CWE-20
5.0