Vulnerability index

Browse CVEs

541 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control Manager CRITICAL 9.8
CVE-2017-11386EPSS 24%

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validatio…

Patch available
Fix from $2,300 2017-08-02
Control Manager CRITICAL 9.8
CVE-2017-11389EPSS 27%

Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-…

Patch available
Fix from $2,300 2017-08-02
Control Manager HIGH 8.8
CVE-2017-11388EPSS 14%

SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provi…

Patch available
Fix from $1,950 2017-08-02
Control Manager HIGH 7.5
CVE-2017-11387EPSS 15%

Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality t…

Patch available
Fix from $1,950 2017-08-02
Control Manager HIGH 7.5
CVE-2017-11390

XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly Z…

Patch available
Fix from $1,950 2017-08-02
Deep Discovery Director CRITICAL 9.8
CVE-2017-11380

Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all …

Patch available
Fix from $2,300 2017-08-01
Deep Discovery Director CRITICAL 9.8
CVE-2017-11381

A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the p…

Patch available
Fix from $2,300 2017-08-01
Deep Discovery Director HIGH 7.5
CVE-2017-11379

Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.

Patch available
Fix from $1,950 2017-08-01
Serverprotect HIGH 7.8
CVE-2017-9036

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.

Patch available
Fix from $1,950 2017-05-26
Serverprotect HIGH 7.4
CVE-2017-9035

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications…

Patch available
Fix from $1,950 2017-05-26
Serverprotect MEDIUM 6.1
CVE-2017-9037

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitr…

Patch available
Fix from $1,600 2017-05-26
Serverprotect CRITICAL 9.8
CVE-2017-9034EPSS 6%

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root…

Patch available
Fix from $2,300 2017-05-26
Serverprotect HIGH 8.8
CVE-2017-9033

Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authe…

Patch available
Fix from $1,950 2017-05-26
Serverprotect MEDIUM 6.1
CVE-2017-9032

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remote attackers to inject arbitr…

Patch available
Fix from $1,600 2017-05-26
Officescan MEDIUM 6.1
CVE-2017-8801

Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked …

Mitigation only
Fix from $1,600 2017-05-05
Officescan HIGH 8.8
CVE-2017-5481

Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an …

Patch available
Fix from $1,950 2017-05-03
Threat Discovery Appliance CRITICAL 9.8
CVE-2016-8584EPSS 6%

Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication…

Fix: after 2.6.1062
Fix from $2,300 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8585EPSS 7%

admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8586EPSS 6%

detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8589EPSS 6%

log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8590EPSS 6%

log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8591EPSS 6%

log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8592EPSS 6%

log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as …

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8593EPSS 7%

Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 7.3
CVE-2016-8587

dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 7.3
CVE-2016-8588

The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Interscan Messaging Security Virtual Appliance MEDIUM 6.1
CVE-2017-7896

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.

Fix: after 9.1
Fix from $1,600 2017-04-18
Threat Discovery Appliance CRITICAL 9.8
CVE-2016-7547EPSS 93%

A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interf…

Patch available
Fix from $2,300 2017-04-12
Threat Discovery Appliance CRITICAL 9.8
CVE-2016-7552EPSS 93%

On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated at…

Patch available
Fix from $2,300 2017-04-12
Interscan Web Security Virtual Appliance MEDIUM 6.5
CVE-2017-6338

Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user…

Fix: after 6.5
Fix from $1,600 2017-04-05