Show filters
493 Total Results
Displaying 181-190 of 493
Sort by:
Attacker Value
Unknown

CVE-2021-32458

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-32459

Disclosure Date: May 27, 2021 (last updated February 22, 2025)
Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-32457

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-31519

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-28649

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-31520

Disclosure Date: May 10, 2021 (last updated February 22, 2025)
A weak session token authentication bypass vulnerability in Trend Micro IM Security 1.6 and 1.6.5 could allow an remote attacker to guess currently logged-in administrators' session session token in order to gain access to the product's web management interface.
Attacker Value
Unknown

CVE-2021-31518

Disclosure Date: May 05, 2021 (last updated November 28, 2024)
Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517.
Attacker Value
Unknown

CVE-2021-31517

Disclosure Date: May 05, 2021 (last updated November 28, 2024)
Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31518.
Attacker Value
Unknown

CVE-2021-28648

Disclosure Date: April 22, 2021 (last updated February 22, 2025)
Trend Micro Antivirus for Mac 2020 v10.5 and 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-28646

Disclosure Date: April 13, 2021 (last updated February 22, 2025)
An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations.