VYPR

Trend Micro

by Trend Micro

CVEs (83)

  • CVE-2020-25770MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24565MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2020-24564MedSep 29, 2020
    risk 0.36cvss 5.5epss 0.01

    An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute…

  • CVE-2021-25243MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.

  • CVE-2021-25242MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information.

  • CVE-2021-25241MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.

  • CVE-2021-25240MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information.

  • CVE-2021-25239MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.

  • CVE-2021-25237MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about the managing port used by agents.

  • CVE-2021-25235MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file.

  • CVE-2021-25234MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file.

  • CVE-2021-25233MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file.

  • CVE-2021-25232MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database.

  • CVE-2021-25231MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file.

  • CVE-2021-25230MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file.

  • CVE-2021-25229MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.

  • CVE-2021-25228MedFeb 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history.

  • CVE-2020-28583MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.

  • CVE-2020-28582MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.

  • CVE-2020-28577MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.

Page 4 of 5