Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2017-6339
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,…
Interscan Web Security Virtual Appliance
after 6.5
MEDIUM 5.4
CVE-2017-6340
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which …
Interscan Web Security Virtual Appliance
after 6.5
MEDIUM 5.9
CVE-2016-9319
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.
Mobile Security
after 9.7
MEDIUM 6.7
CVE-2017-5565
Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (…
Antivirus\+
after 11.1.1005
HIGH 8.8
CVE-2017-6398EPSS 54%
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal comman…
Interscan Messaging Security Virtual Appliance
No fix yet
HIGH 7.8
CVE-2017-6798
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micr…
Endpoint Sensor
after 1.6
CRITICAL 9.9
CVE-2016-9269EPSS 13%
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_…
Interscan Web Security Virtual Appliance
after 6.5
HIGH 8.8
CVE-2016-9315EPSS 9%
Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance …
Interscan Web Security Virtual Appliance
after 6.5
HIGH 7.8
CVE-2016-9314
Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6…
Interscan Web Security Virtual Appliance
after 6.5
MEDIUM 5.4
CVE-2016-9316
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Sec…
Interscan Web Security Virtual Appliance
after 6.5
CRITICAL 9.1
CVE-2016-6269
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before buil…
Smart Protection Server
Patch available
HIGH 8.8
CVE-2016-6266EPSS 8%
ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote aut…
Smart Protection Server
Patch available
HIGH 8.8
CVE-2016-6267EPSS 55%
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated …
Smart Protection Server
Patch available
HIGH 8.8
CVE-2016-6270EPSS 6%
The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 all…
Virtual Mobile Infrastructure
No fix yet
HIGH 7.8
CVE-2016-6268
Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arb…
Smart Protection Server
Patch available
MEDIUM 6.1
CVE-2016-1226
Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via…
Internet Security
Mitigation only
MEDIUM 6.5
CVE-2016-1225
Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.
Internet Security
No fix yet
MEDIUM 6.1
CVE-2016-1224
CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to …
Worry Free Business Security
Mitigation only
MEDIUM 5.3
CVE-2016-1223
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 all…
Officescan
Mitigation only
CRITICAL 9.8
CVE-2016-4351
SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote a…
Email Encryption Gateway
after 5.5
CRITICAL 9.8
CVE-2016-3987EPSS 22%
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef…
Password Manager
No fix yet
MEDIUM 5.5
CVE-2015-2873
Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7…
Deep Discovery Inspector
Patch available
HIGH 7.2
CVE-2014-9641
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitra…
Tmeext.sys
after 2.0.0.1014
MEDIUM 6.8
CVE-2012-2996
Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allo…
Interscan Messaging Security Suite
No fix yet
MEDIUM 6.2
CVE-2010-5179
Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and ex…
Internet Security 2010
Mitigation only
HIGH 9.3
CVE-2010-3189EPSS 39%
The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers t…
Internet Security
Patch available
MEDIUM 5.0
CVE-2010-0564
Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029…
Officescan
after 8.0
HIGH 7.2
CVE-2009-0686
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows l…
Internet Security
No fix yet
MEDIUM 6.0
CVE-2009-0613
Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended pe…
Interscan Web Security Suite
Mitigation only
CRITICAL 9.8
CVE-2008-2433EPSS 11%
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6…
Client Server Messaging Suite
after 8.0