Vulnerabilities (CVE)

Filtered by vendor Proofpoint Subscribe
Filtered by product Enterprise Protection
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5771 1 Proofpoint 1 Enterprise Protection 2023-11-14 N/A 6.1 MEDIUM
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages.  This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions.
CVE-2021-39304 1 Proofpoint 1 Enterprise Protection 2021-10-19 5.0 MEDIUM 7.5 HIGH
Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.
CVE-2020-14009 1 Proofpoint 1 Enterprise Protection 2021-05-19 6.8 MEDIUM 6.3 MEDIUM
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The vulnerability exists because messages with certain crafted and malformed multipart structures are not properly handled.
CVE-2019-19680 1 Proofpoint 1 Enterprise Protection 2021-03-04 6.8 MEDIUM 8.8 HIGH
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal entries for transmitted files) by sending malformed (not RFC compliant) multipart email.