Show filters
493 Total Results
Displaying 351-360 of 493
Sort by:
Attacker Value
Unknown

CVE-2018-6237

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial of service (DoS) situation.
0
Attacker Value
Unknown

CVE-2018-6236

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-6235

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222814 by the tmnciesc.sys driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10350

Disclosure Date: May 25, 2018 (last updated November 26, 2024)
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs\_bwlists\_handler.php. Authentication is required in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10355

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10353

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive information on vulnerable installations due to a flaw in the formChangePass class. Authentication is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10357

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10351

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10356

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is required to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2018-10354

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this vulnerability.
0