Show filters
108 Total Results
Displaying 61-70 of 108
Sort by:
Attacker Value
Unknown
CVE-2017-14085
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
0
Attacker Value
Unknown
CVE-2017-14086
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.
0
Attacker Value
Unknown
CVE-2017-14089
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.
0
Attacker Value
Unknown
CVE-2017-14083
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.
0
Attacker Value
Unknown
CVE-2017-14087
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
0
Attacker Value
Unknown
CVE-2017-14084
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.
0
Attacker Value
Unknown
CVE-2017-14088
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
0
Attacker Value
Unknown
CVE-2017-11393
Disclosure Date: August 03, 2017 (last updated November 26, 2024)
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.
0
Attacker Value
Unknown
CVE-2017-11394
Disclosure Date: August 03, 2017 (last updated November 26, 2024)
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.
0
Attacker Value
Unknown
CVE-2017-8801
Disclosure Date: May 05, 2017 (last updated November 26, 2024)
Trend Micro OfficeScan 11.0 before SP1 CP 6325 (with Agent Module Build before 6152) and XG before CP 1352 has XSS via a crafted URI using a blocked website.
0