Show filters
156 Total Results
Displaying 121-130 of 156
Sort by:
Attacker Value
Unknown
CVE-2008-1366
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers a NULL pointer dereference.
0
Attacker Value
Unknown
CVE-2008-1365
Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.
0
Attacker Value
Unknown
CVE-2008-1221
Disclosure Date: March 10, 2008 (last updated October 04, 2023)
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.
0
Attacker Value
Unknown
CVE-2007-4649
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
0
Attacker Value
Unknown
CVE-2007-3455
Disclosure Date: June 27, 2007 (last updated October 04, 2023)
cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information."
0
Attacker Value
Unknown
CVE-2007-3454
Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library.
0
Attacker Value
Unknown
CVE-2007-2687
Disclosure Date: May 24, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan before 9.0.718.1 allows remote attackers to execute arbitrary code via a long command.
0
Attacker Value
Unknown
CVE-2007-1670
Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
0
Attacker Value
Unknown
CVE-2007-0655
Disclosure Date: May 02, 2007 (last updated October 04, 2023)
The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222.
0
Attacker Value
Unknown
CVE-2007-0325
Disclosure Date: February 20, 2007 (last updated October 04, 2023)
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.
0