Show filters
493 Total Results
Displaying 311-320 of 493
Sort by:
Attacker Value
Unknown

CVE-2019-15626

Disclosure Date: October 17, 2019 (last updated November 27, 2024)
The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit initial LDAP communication in clear text. This may result in confidentiality impact but does not impact integrity or availability.
Attacker Value
Unknown

CVE-2019-9488

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, for the attack to be possible, the attacker must have root/admin access to a protected host which is authorized to communicate with the Deep Security Manager (DSM).
Attacker Value
Unknown

CVE-2019-19697

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administrator privileges on the target machine in order to exploit the vulnerability.
Attacker Value
Unknown

CVE-2019-14686

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.
0
Attacker Value
Unknown

CVE-2019-14685

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
0
Attacker Value
Unknown

CVE-2019-14684

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.
0
Attacker Value
Unknown

CVE-2019-14687

Disclosure Date: August 20, 2019 (last updated November 08, 2023)
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.
0
Attacker Value
Unknown

CVE-2019-9492

Disclosure Date: July 26, 2019 (last updated November 27, 2024)
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
0
Attacker Value
Unknown

CVE-2019-20357

Disclosure Date: April 19, 2019 (last updated February 21, 2025)
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
Attacker Value
Unknown

CVE-2019-9490

Disclosure Date: April 05, 2019 (last updated November 27, 2024)
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose administrative credentials. An attacker must be an authenticated user in order to exploit the vulnerability.
0