Vulnerabilities
Vulnerable Software
Trendmicro:  Security Vulnerabilities
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.
CVSS Score
7.5
EPSS Score
0.055
Published
2017-10-06
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.
CVSS Score
8.1
EPSS Score
0.101
Published
2017-10-06
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.
CVSS Score
5.3
EPSS Score
0.057
Published
2017-10-06
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.
CVSS Score
7.5
EPSS Score
0.079
Published
2017-10-06
Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.
CVSS Score
8.8
EPSS Score
0.141
Published
2017-09-22
Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.
CVSS Score
7.2
EPSS Score
0.032
Published
2017-09-22
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
CVSS Score
9.8
EPSS Score
0.502
Published
2017-09-22
Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
CVSS Score
8.8
EPSS Score
0.109
Published
2017-09-22
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.
CVSS Score
9.8
EPSS Score
0.03
Published
2017-09-22
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
CVSS Score
8.8
EPSS Score
0.166
Published
2017-09-22


Contact Us

Shodan ® - All rights reserved