VYPR

Officescan

by Trend Micro

CVEs (103)

  • CVE-2020-28583MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.

  • CVE-2020-28582MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.

  • CVE-2020-28577MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.

  • CVE-2020-28576MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.

  • CVE-2020-28573MedDec 1, 2020
    risk 0.35cvss 5.3epss 0.03

    An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal the total agents managed by the server.

  • CVE-2016-1223MedJun 19, 2016
    risk 0.35cvss 5.3epss 0.04

    Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2019-19691MedDec 20, 2019
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this…

  • CVE-2018-10507MedJun 12, 2018
    risk 0.32cvss 4.4epss 0.01

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthorized Change Prevention inoperable on vulnerable installations. An attacker must already have administrator privileges in order to…

  • CVE-2018-15364MedAug 30, 2018
    risk 0.31cvss 4.7epss 0.02

    A Named Pipe Request Processing Out-of-Bounds Read Information Disclosure vulnerability in Trend Micro OfficeScan XG (12.0) could allow a local attacker to disclose sensitive information on vulnerable installations. An attacker must first obtain the ability to execute…

  • CVE-2018-10506MedJun 8, 2018
    risk 0.31cvss 4.7epss 0.01

    A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to disclose sensitive information on vulnerable installations due to a flaw within the processing of IOCTL 0x220004 by the TMWFP driver. An attacker…

  • CVE-2008-3364Jul 30, 2008
    risk 0.06cvss epss 0.33

    Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and…

  • CVE-2007-0325Feb 20, 2007
    risk 0.06cvss epss 0.34

    Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow…

  • CVE-2008-2439Oct 3, 2008
    risk 0.05cvss epss 0.20

    Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before…

  • CVE-2003-1341Dec 31, 2003
    risk 0.04cvss epss 0.08

    The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.

  • CVE-2000-0204Feb 28, 2000
    risk 0.04cvss epss 0.07

    The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.

  • CVE-2009-1435Apr 27, 2009
    risk 0.03cvss epss 0.01

    NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

  • CVE-2002-1349Dec 18, 2002
    risk 0.03cvss epss 0.01

    Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a long input string to TCP port 110 (POP3).

  • CVE-2008-3865Jan 21, 2009
    risk 0.01cvss epss 0.06

    Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers…

  • CVE-2008-3862Oct 23, 2008
    risk 0.01cvss epss 0.18

    Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form…

  • CVE-2008-2437Sep 16, 2008
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long…

Page 4 of 6