Show filters
132 Total Results
Displaying 21-30 of 132
Sort by:
Attacker Value
Unknown

CVE-2024-36304

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-36302

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar to, but not identical to, CVE-2024-36303.
0
Attacker Value
Unknown

CVE-2024-32849

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.
0
Attacker Value
Unknown

CVE-2024-32849

Disclosure Date: June 10, 2024 (last updated June 11, 2024)
Trend Micro Security 17.x (Consumer) is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.
0
Attacker Value
Unknown

CVE-2016-5840

Disclosure Date: June 30, 2016 (last updated November 25, 2024)
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.
0
Attacker Value
Unknown

CVE-2016-3664

Disclosure Date: May 23, 2016 (last updated November 25, 2024)
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2015-3326

Disclosure Date: May 14, 2015 (last updated October 05, 2023)
Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.
0
Attacker Value
Unknown

CVE-2012-2998

Disclosure Date: September 28, 2012 (last updated October 05, 2023)
SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-5001

Disclosure Date: December 25, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.
0
Attacker Value
Unknown

CVE-2008-3864

Disclosure Date: January 21, 2009 (last updated October 04, 2023)
The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.
0