Show filters
156 Total Results
Displaying 71-80 of 156
Sort by:
Attacker Value
Unknown

CVE-2019-18189

Disclosure Date: October 28, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
Attacker Value
Unknown

CVE-2019-10423

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins CodeScan Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Attacker Value
Unknown

CVE-2019-9492

Disclosure Date: July 26, 2019 (last updated November 27, 2024)
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
0
Attacker Value
Unknown

CVE-2019-9489

Disclosure Date: April 05, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
0
Attacker Value
Unknown

CVE-2018-18331

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.
0
Attacker Value
Unknown

CVE-2018-18332

Disclosure Date: December 21, 2018 (last updated November 27, 2024)
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.
0
Attacker Value
Unknown

CVE-2018-18388

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222.
0
Attacker Value
Unknown

CVE-2018-15364

Disclosure Date: August 30, 2018 (last updated November 27, 2024)
A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit the vulnerability.
0
Attacker Value
Unknown

CVE-2018-10098

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD).
0
Attacker Value
Unknown

CVE-2018-3608

Disclosure Date: July 06, 2018 (last updated November 27, 2024)
A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable system in such a way that malicious code could be injected into other processes.
0