← Vulnerability feed

Vulnerability record · CVE-2014-2537 · published 18 March 2014

CVE-2014-2537: Sophos unified threat management software vulnerability

Sophos · Unified Threat Management Software

Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

7.8 CVSS 2.0 High EPSS 3.1% · top 12.9% CWE-399 · CWE-399
7.8CVSS 2.0 base score
3.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2537 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-25223Sophos SG UTM WebAdmin OS command injection allows remote code executionSophos SG UTM WebAdmin contains an OS command injection flaw (CWE-78) that permits remote code execution. It affects versions before v9.705 MR5, v9.6…KEVEPSS 97%analysed10.0CVE-2013-5932Sophos unified threat management software vulnerabilityUnspecified vulnerability in WebAdmin in Sophos UTM (aka Astaro Security Gateway) before 9.105 has unknown impact and attack vectors.EPSS 5.4%8.8CVE-2022-0386Sophos unified threat management sql injection vulnerabilityA post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version…EPSS 1.2%8.1CVE-2015-7547glibc libresolv getaddrinfo stack buffer overflowMultiple stack-based buffer overflows exist in the send_dg and send_vc functions of the libresolv library in GNU C Library (glibc) before 2.23. A cra…EPSS 91%analysed8.1CVE-2016-0778Oracle linux memory buffer overflow vulnerabilityThe (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy …EPSS 21%7.8CVE-2022-0652Sophos unified threat management sensitive information in log file vulnerabilityConfd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to…EPSS 0.19%6.5CVE-2016-0777OpenSSH client memory disclosure via roaming resend_bytesThe resend_bytes function in the OpenSSH client's roaming_common.c mishandles buffer resend requests, allowing a malicious or compromised SSH server …EPSS 63%analysed6.1CVE-2016-2046Sophos unified threat management software cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or …EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2014-2537), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.