Vulnerability index

Browse CVEs

541 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2017-6339 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,… Interscan Web Security Virtual Appliance after 6.5 Fix from $1,6002017-04-05 MEDIUM 5.4 CVE-2017-6340 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which … Interscan Web Security Virtual Appliance after 6.5 Fix from $1,6002017-04-05 MEDIUM 5.9 CVE-2016-9319 There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398. Mobile Security after 9.7 Fix from $1,6002017-03-31 MEDIUM 6.7 CVE-2017-5565 Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (… Antivirus\+ after 11.1.1005 Fix from $1,6002017-03-21 HIGH 8.8 CVE-2017-6398EPSS 54% An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal comman… Interscan Messaging Security Virtual Appliance No fix yet Fix from $1,9502017-03-14 HIGH 7.8 CVE-2017-6798 Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micr… Endpoint Sensor after 1.6 Fix from $1,9502017-03-10 CRITICAL 9.9 CVE-2016-9269EPSS 13% Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_… Interscan Web Security Virtual Appliance after 6.5 Fix from $2,3002017-02-21 HIGH 8.8 CVE-2016-9315EPSS 9% Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance … Interscan Web Security Virtual Appliance after 6.5 Fix from $1,9502017-02-21 HIGH 7.8 CVE-2016-9314 Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6… Interscan Web Security Virtual Appliance after 6.5 Fix from $1,9502017-02-21 MEDIUM 5.4 CVE-2016-9316 Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Sec… Interscan Web Security Virtual Appliance after 6.5 Fix from $1,6002017-02-21 CRITICAL 9.1 CVE-2016-6269 Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before buil… Smart Protection Server Patch available Fix from $2,3002017-01-30 HIGH 8.8 CVE-2016-6266EPSS 8% ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote aut… Smart Protection Server Patch available Fix from $1,9502017-01-30 HIGH 8.8 CVE-2016-6267EPSS 55% SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated … Smart Protection Server Patch available Fix from $1,9502017-01-30 HIGH 8.8 CVE-2016-6270EPSS 6% The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 all… Virtual Mobile Infrastructure No fix yet Fix from $1,9502017-01-30 HIGH 7.8 CVE-2016-6268 Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arb… Smart Protection Server Patch available Fix from $1,9502017-01-30 MEDIUM 6.1 CVE-2016-1226 Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via… Internet Security Mitigation only Fix from $1,6002016-06-19 MEDIUM 6.5 CVE-2016-1225 Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors. Internet Security No fix yet Fix from $1,6002016-06-19 MEDIUM 6.1 CVE-2016-1224 CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to … Worry Free Business Security Mitigation only Fix from $1,6002016-06-19 MEDIUM 5.3 CVE-2016-1223 Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 all… Officescan Mitigation only Fix from $1,6002016-06-19 CRITICAL 9.8 CVE-2016-4351 SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote a… Email Encryption Gateway after 5.5 Fix from $2,3002016-05-05 CRITICAL 9.8 CVE-2016-3987EPSS 22% The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef… Password Manager No fix yet Fix from $2,3002016-04-12 MEDIUM 5.5 CVE-2015-2873 Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7… Deep Discovery Inspector Patch available Fix from $1,6002015-08-23 HIGH 7.2 CVE-2014-9641 The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitra… Tmeext.sys after 2.0.0.1014 Fix from $1,9502015-02-06 MEDIUM 6.8 CVE-2012-2996 Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allo… Interscan Messaging Security Suite No fix yet Fix from $1,6002012-09-17 MEDIUM 6.2 CVE-2010-5179 Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and ex… Internet Security 2010 Mitigation only Fix from $1,6002012-08-25 HIGH 9.3 CVE-2010-3189EPSS 39% The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers t… Internet Security Patch available Fix from $1,9502010-08-31 MEDIUM 5.0 CVE-2010-0564 Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029… Officescan after 8.0 Fix from $1,6002010-02-10 HIGH 7.2 CVE-2009-0686 The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows l… Internet Security No fix yet Fix from $1,9502009-04-01 MEDIUM 6.0 CVE-2009-0613 Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended pe… Interscan Web Security Suite Mitigation only Fix from $1,6002009-02-17 CRITICAL 9.8 CVE-2008-2433EPSS 11% The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6… Client Server Messaging Suite after 8.0 Fix from $2,3002008-08-27