
CVE-2006-6335 – Sophos Anti-Virus SIT Archive Parsing Buffer Overflow Vulnerability
https://notcve.org/view.php?id=CVE-2006-6335
12 Dec 2006 — Multiple buffer overflows in Sophos Anti-Virus scanning engine before 2.40 allow remote attackers to execute arbitrary code via (1) a SIT archive with a long filename that is not null-terminated, which triggers a heap-based overflow in veex.dll due to improper length calculation, and (2) a CPIO archive, with a long filename that is not null-terminated, which triggers a stack-based overflow in veex.dll. Múltiples desbordamientos de búfer en el motor de escaneo Sophos Anti-Virus en versiones anteriores a la 2... • http://secunia.com/advisories/23325 •

CVE-2005-4680
https://notcve.org/view.php?id=CVE-2005-4680
31 Dec 2005 — Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned. • http://www.sophos.com/support/knowledgebase/article/3803.html •