Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Enterprise_protection
(Proofpoint)| Repositories |
Unknown: This might be proprietary software. |
| #Vulnerabilities | 14 |
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2025-04-28 | CVE-2024-10635 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system. | Enterprise_protection | 5.3 | ||
| 2025-04-28 | CVE-2024-10635 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system. | Enterprise_protection | 5.3 | ||
| 2025-04-28 | CVE-2024-10635 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME attachment with an opaque signature. When opened by a recipient in a downstream email client, the malicious attachment could cause partial loss of integrity and confidentiality to their system. | Enterprise_protection | 5.3 | ||
| 2022-11-17 | CVE-2021-31608 | Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. | Enterprise_protection | 4.3 | ||
| 2021-05-07 | CVE-2020-14009 | Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled. | Enterprise_protection | 6.3 | ||
| 2021-10-13 | CVE-2021-39304 | Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass. | Enterprise_protection | 7.5 | ||
| 2022-12-06 | CVE-2022-46332 | The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below. | Enterprise_protection | 9.6 | ||
| 2022-12-06 | CVE-2022-46333 | The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below. | Enterprise_protection | 7.2 | ||
| 2022-12-21 | CVE-2022-46334 | Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below. | Enterprise_protection | 7.8 | ||
| 2023-03-08 | CVE-2023-0089 | The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below. | Enterprise_protection | 8.8 |