Vulnerability index

Browse CVEs

541 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Interscan Web Security Virtual Appliance MEDIUM 6.5
CVE-2017-6339

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,…

Fix: after 6.5
Fix from $1,600 2017-04-05
Interscan Web Security Virtual Appliance MEDIUM 5.4
CVE-2017-6340

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which …

Fix: after 6.5
Fix from $1,600 2017-04-05
Mobile Security MEDIUM 5.9
CVE-2016-9319

There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.

Fix: after 9.7
Fix from $1,600 2017-03-31
Antivirus\+ MEDIUM 6.7
CVE-2017-5565

Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (…

Fix: after 11.1.1005
Fix from $1,600 2017-03-21
Interscan Messaging Security Virtual Appliance HIGH 8.8
CVE-2017-6398EPSS 54%

An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal comman…

No fix yet
Fix from $1,950 2017-03-14
Endpoint Sensor HIGH 7.8
CVE-2017-6798

Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micr…

Fix: after 1.6
Fix from $1,950 2017-03-10
Interscan Web Security Virtual Appliance CRITICAL 9.9
CVE-2016-9269EPSS 13%

Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_…

Fix: after 6.5
Fix from $2,300 2017-02-21
Interscan Web Security Virtual Appliance HIGH 8.8
CVE-2016-9315EPSS 9%

Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance …

Fix: after 6.5
Fix from $1,950 2017-02-21
Interscan Web Security Virtual Appliance HIGH 7.8
CVE-2016-9314

Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6…

Fix: after 6.5
Fix from $1,950 2017-02-21
Interscan Web Security Virtual Appliance MEDIUM 5.4
CVE-2016-9316

Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Sec…

Fix: after 6.5
Fix from $1,600 2017-02-21
Smart Protection Server CRITICAL 9.1
CVE-2016-6269

Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before buil…

Patch available
Fix from $2,300 2017-01-30
Smart Protection Server HIGH 8.8
CVE-2016-6266EPSS 8%

ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote aut…

Patch available
Fix from $1,950 2017-01-30
Smart Protection Server HIGH 8.8
CVE-2016-6267EPSS 55%

SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated …

Patch available
Fix from $1,950 2017-01-30
Virtual Mobile Infrastructure HIGH 8.8
CVE-2016-6270EPSS 6%

The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 all…

No fix yet
Fix from $1,950 2017-01-30
Smart Protection Server HIGH 7.8
CVE-2016-6268

Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arb…

Patch available
Fix from $1,950 2017-01-30
Internet Security MEDIUM 6.1
CVE-2016-1226

Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via…

Mitigation only
Fix from $1,600 2016-06-19
Internet Security MEDIUM 6.5
CVE-2016-1225

Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.

No fix yet
Fix from $1,600 2016-06-19
Worry Free Business Security MEDIUM 6.1
CVE-2016-1224

CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to …

Mitigation only
Fix from $1,600 2016-06-19
Officescan MEDIUM 5.3
CVE-2016-1223

Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 all…

Mitigation only
Fix from $1,600 2016-06-19
Email Encryption Gateway CRITICAL 9.8
CVE-2016-4351

SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote a…

Fix: after 5.5
Fix from $2,300 2016-05-05
Password Manager CRITICAL 9.8
CVE-2016-3987EPSS 22%

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef…

No fix yet
Fix from $2,300 2016-04-12
Deep Discovery Inspector MEDIUM 5.5
CVE-2015-2873

Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7…

Patch available
Fix from $1,600 2015-08-23
Tmeext.sys HIGH 7.2
CVE-2014-9641

The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitra…

Fix: after 2.0.0.1014
Fix from $1,950 2015-02-06
Interscan Messaging Security Suite MEDIUM 6.8
CVE-2012-2996

Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allo…

No fix yet
Fix from $1,600 2012-09-17
Internet Security 2010 MEDIUM 6.2
CVE-2010-5179

Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and ex…

Mitigation only
Fix from $1,600 2012-08-25
Internet Security HIGH 9.3
CVE-2010-3189EPSS 39%

The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers t…

Patch available
Fix from $1,950 2010-08-31
Officescan MEDIUM 5.0
CVE-2010-0564

Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029…

Fix: after 8.0
Fix from $1,600 2010-02-10
Internet Security HIGH 7.2
CVE-2009-0686

The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows l…

No fix yet
Fix from $1,950 2009-04-01
Interscan Web Security Suite MEDIUM 6.0
CVE-2009-0613

Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended pe…

Mitigation only
Fix from $1,600 2009-02-17
Client Server Messaging Suite CRITICAL 9.8
CVE-2008-2433EPSS 11%

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6…

Fix: after 8.0
Fix from $2,300 2008-08-27