Vulnerability index

Browse CVEs

541 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smart Protection Server HIGH 8.1
CVE-2017-14095EPSS 12%

A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command executio…

Fix: after 3.2
Fix from $1,950 2018-01-19
Mobile Security HIGH 7.5
CVE-2017-14082

An uninitialized pointer information disclosure vulnerability in Trend Micro Mobile Security (Enterprise) versions 9.7 and below could allow an unaut…

Fix: after 9.7
Fix from $1,950 2018-01-19
Smart Protection Server MEDIUM 6.1
CVE-2017-14096

A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker …

Fix: after 3.2
Fix from $1,600 2018-01-19
Scanmail CRITICAL 9.1
CVE-2017-14090

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

Patch available
Fix from $2,300 2017-12-16
Scanmail HIGH 8.8
CVE-2017-14092

The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated request…

Patch available
Fix from $1,950 2017-12-16
Scanmail HIGH 7.5
CVE-2017-14091

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Upda…

Patch available
Fix from $1,950 2017-12-16
Scanmail MEDIUM 6.1
CVE-2017-14093

The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.

Patch available
Fix from $1,600 2017-12-16
Encryption For Email HIGH 7.8
CVE-2017-11397

A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to e…

Fix: after 5.6.0.1073
Fix from $1,950 2017-12-16
Officescan CRITICAL 9.8
CVE-2017-14089EPSS 10%

An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Offic…

Patch available
Fix from $2,300 2017-10-06
Officescan HIGH 7.5
CVE-2017-14087EPSS 8%

A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attac…

No fix yet
Fix from $1,950 2017-10-06
Officescan HIGH 7.0
CVE-2017-14088

Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and esc…

Patch available
Fix from $1,950 2017-10-06
Officescan HIGH 8.1
CVE-2017-14084EPSS 10%

A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vuln…

Patch available
Fix from $1,950 2017-10-06
Officescan HIGH 7.5
CVE-2017-14083EPSS 6%

A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryp…

Patch available
Fix from $1,950 2017-10-06
Officescan HIGH 7.5
CVE-2017-14086EPSS 8%

Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the Offic…

Patch available
Fix from $1,950 2017-10-06
Officescan MEDIUM 5.3
CVE-2017-14085EPSS 6%

Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to …

Patch available
Fix from $1,600 2017-10-06
Mobile Security CRITICAL 9.8
CVE-2017-14078EPSS 50%

SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary cod…

Patch available
Fix from $2,300 2017-09-22
Mobile Security CRITICAL 9.8
CVE-2017-14080

Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific par…

Patch available
Fix from $2,300 2017-09-22
Smart Protection Server HIGH 8.8
CVE-2017-11395EPSS 14%

Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authen…

Patch available
Fix from $1,950 2017-09-22
Mobile Security HIGH 8.8
CVE-2017-14079EPSS 11%

Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on…

Patch available
Fix from $1,950 2017-09-22
Mobile Security HIGH 8.8
CVE-2017-14081EPSS 17%

Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arb…

Fix: after 9.7
Fix from $1,950 2017-09-22
Interscan Web Security Virtual Appliance HIGH 7.2
CVE-2017-11396

Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attack…

Patch available
Fix from $1,950 2017-09-22
Control Manager HIGH 7.5
CVE-2016-6220

Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.

Patch available
Fix from $1,950 2017-08-07
Officescan CRITICAL 9.8
CVE-2017-11393EPSS 16%

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable instal…

Patch available
Fix from $2,300 2017-08-03
Officescan CRITICAL 9.8
CVE-2017-11394EPSS 67%

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable instal…

Patch available
Fix from $2,300 2017-08-03
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-11391EPSS 62%

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-03
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-11392EPSS 34%

Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2017-08-03
Deep Discovery Email Inspector HIGH 7.5
CVE-2017-11382

Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable i…

Patch available
Fix from $1,950 2017-08-03
Control Manager CRITICAL 9.8
CVE-2017-11383EPSS 39%

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validatio…

Patch available
Fix from $2,300 2017-08-02
Control Manager CRITICAL 9.8
CVE-2017-11384EPSS 39%

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validatio…

Patch available
Fix from $2,300 2017-08-02
Control Manager CRITICAL 9.8
CVE-2017-11385EPSS 39%

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validatio…

Patch available
Fix from $2,300 2017-08-02