Show filters
125 Total Results
Displaying 21-30 of 125
Sort by:
Attacker Value
Unknown
CVE-2021-25252
Disclosure Date: March 03, 2021 (last updated February 22, 2025)
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
0
Attacker Value
Unknown
CVE-2021-1271
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious data into a specific data field in an affected interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface.
0
Attacker Value
Unknown
CVE-2021-1129
Disclosure Date: January 20, 2021 (last updated February 22, 2025)
A vulnerability in the authentication for the general purpose APIs implementation of Cisco Email Security Appliance (ESA), Cisco Content Security Management Appliance (SMA), and Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to access general system information and certain configuration information from an affected device. The vulnerability exists because a secure authentication token is not required when authenticating to the general purpose API. An attacker could exploit this vulnerability by sending a crafted request for information to the general purpose API on an affected device. A successful exploit could allow the attacker to obtain system and configuration information from the affected device, resulting in an unauthorized information disclosure.
0
Attacker Value
Unknown
CVE-2020-8463
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.
0
Attacker Value
Unknown
CVE-2020-27010
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product in a manner separate from the similar CVE-2020-8462.
0
Attacker Value
Unknown
CVE-2020-8466
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.
0
Attacker Value
Unknown
CVE-2020-8462
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.
0
Attacker Value
Unknown
CVE-2020-8464
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.
0
Attacker Value
Unknown
CVE-2020-8465
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.
0
Attacker Value
Unknown
CVE-2020-8461
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without requiring a valid CSRF token.
0