| CVE-2017-14089 |
critical |
9.8 |
10.0 |
EXP |
|
trendmicro |
9y ago |
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and ca… |
| CVE-2017-11394 |
critical |
9.8 |
10.0 |
EXP |
|
trendmicro |
9y ago |
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by par… |
| CVE-2016-7552 |
critical |
9.8 |
10.0 |
EXP |
|
trendmicro |
9y ago |
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can… |
| CVE-2016-7547 |
critical |
9.8 |
10.0 |
EXP |
|
trendmicro |
9y ago |
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface. |
| CVE-2016-9269 |
critical |
9.9 |
10.0 |
EXP |
|
trendmicro |
9y ago |
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated,… |
| CVE-2016-3987 |
critical |
9.8 |
10.0 |
EXP |
|
trendmicro |
10y ago |
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. |
| CVE-2010-3189 |
critical |
— |
10.0 |
EXP |
|
trendmicro |
16y ago |
The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address th… |