Show filters
156 Total Results
Displaying 101-110 of 156
Sort by:
Attacker Value
Unknown
CVE-2017-11394
Disclosure Date: August 03, 2017 (last updated November 26, 2024)
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
0
Attacker Value
Unknown
CVE-2017-8801
Disclosure Date: May 05, 2017 (last updated November 26, 2024)
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
0
Attacker Value
Unknown
CVE-2017-5481
Disclosure Date: May 03, 2017 (last updated November 26, 2024)
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.
0
Attacker Value
Unknown
CVE-2016-8348
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.
0
Attacker Value
Unknown
CVE-2016-1223
Disclosure Date: June 19, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2009-3735
Disclosure Date: February 11, 2010 (last updated October 04, 2023)
The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.
0
Attacker Value
Unknown
CVE-2010-0564
Disclosure Date: February 10, 2010 (last updated October 04, 2023)
Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029, allows attackers to cause a denial of service (crash or OfficeScan hang) via unspecified vectors. NOTE: it is likely that this issue also affects tmufeng.dll before 2.0.0.1049 for OfficeScan 10.0.
0
Attacker Value
Unknown
CVE-2009-1435
Disclosure Date: April 27, 2009 (last updated October 04, 2023)
NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-3864
Disclosure Date: January 21, 2009 (last updated October 04, 2023)
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.
0
Attacker Value
Unknown
CVE-2008-3865
Disclosure Date: January 21, 2009 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet with a small value in an unspecified size field.
0