MidnightBSD

Advisories for trendmicro

CVE-2006-1380 HIGH

ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro interscan_messaging_security_suite 5.5
CVE-2008-2433 HIGH

The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-330,

Products Affected

Vendor Product Version
trendmicro worry-free_business_security 5.0
trendmicro client_server_messaging_suite 3.5
trendmicro client_server_messaging_suite 3.6
trendmicro officescan *
CVE-2009-0612 MEDIUM

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
trendmicro interscan_web_security_virtual_appliance 3.1
trendmicro interscan_web_security_suite 3.1
trendmicro interscan_web_security_suite 2.5
CVE-2009-0613 MEDIUM

Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro interscan_web_security_suite 3.1
CVE-2009-0686 HIGH

The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
trendmicro internet_security 2009
trendmicro internet_security 2008
CVE-2009-1435 LOW

NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: LOW

Problem Type: CWE-399,

Products Affected

Vendor Product Version
trendmicro officescan 8.0
CVE-2010-0564 MEDIUM

Buffer overflow in Trend Micro URL Filtering Engine (TMUFE) in OfficeScan 8.0 before SP1 Patch 5 - Build 3510, possibly tmufeng.dll before 3.0.0.1029, allows attackers to cause a denial of service (crash or OfficeScan hang) via unspecified vectors. NOTE: it is likely that this issue also affects tmufeng.dll before 2.0.0.1049 for OfficeScan 10.0.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
trendmicro officescan *
CVE-2010-3189 HIGH

The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
trendmicro internet_security 2010
CVE-2010-5179 MEDIUM

Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-362,

Products Affected

Vendor Product Version
trendmicro internet_security_2010 17.50.1647.0000
CVE-2011-1327 LOW

The Keystroke Encryption feature in Trend Micro Internet Security 2009 (aka Virus Buster 2009 and PC-cillin 2009) does not completely encrypt passwords, which allows local users to obtain sensitive information by leveraging a keylogger.

CVSS 2.0

Severity: LOW

Problem Type: CWE-310,

Products Affected

Vendor Product Version
trendmicro trend_micro_internet_security 2009
CVE-2012-1425 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial \50\4B\03\04 character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
antiy avl_sdk 2.0.3.7
symantec endpoint_protection 11.0
jiangmin jiangmin_antivirus 13.0.900
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
pc_tools pc_tools_antivirus 7.0.3.5
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
avira antivir 7.11.1.163
cat quick_heal 11.00
CVE-2012-1443 MEDIUM

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools AntiVirus 7.0.3.5, F-Prot Antivirus 4.6.2.117, VirusBuster 13.6.151.0, Fortinet Antivirus 4.2.254.0, Antiy Labs AVL SDK 2.0.3.7, K7 AntiVirus 9.77.3565, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Jiangmin Antivirus 13.0.900, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Sophos Anti-Virus 4.61.0, NOD32 Antivirus 5795, Avira AntiVir 7.11.1.163, Norman Antivirus 6.06.12, McAfee Anti-Virus Scanning Engine 5.400.0.1158, Panda Antivirus 10.0.2.7, McAfee Gateway (formerly Webwasher) 2010.1C, Trend Micro AntiVirus 9.120.0.1004, Comodo Antivirus 7424, Bitdefender 7.2, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, nProtect Anti-Virus 2011-01-17.01, AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, avast! Antivirus 4.8.1351.0 and 5.0.677.0, and VBA32 3.12.14.2 allows user-assisted remote attackers to bypass malware detection via a RAR file with an initial MZ character sequence. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different RAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
nprotect nprotect_antivirus 2011-01-17.01
antiy avl_sdk 2.0.3.7
ahnlab v3_internet_security 2011.01.18.00
symantec endpoint_protection 11.0
jiangmin jiangmin_antivirus 13.0.900
pc_tools pc_tools_antivirus 7.0.3.5
avg avg_anti-virus 10.0.0.1190
pandasecurity panda_antivirus 10.0.2.7
sophos sophos_anti-virus 4.61.0
avira antivir 7.11.1.163
alwil avast_antivirus 5.0.677.0
cat quick_heal 11.00
anti-virus vba32 3.12.14.2
microsoft security_essentials 2.0
clamav clamav 0.96.4
alwil avast_antivirus 4.8.1351.0
virusbuster virusbuster 13.6.151.0
eset nod32_antivirus 5795
f-secure f-secure_anti-virus 9.0.16160.0
norman norman_antivirus_&_antispyware 6.06.12
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
k7computing antivirus 9.77.3565
aladdin esafe 7.0.17.0
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
comodo comodo_antivirus 7424
CVE-2012-1448 MEDIUM

The CAB file parser in Quick Heal (aka Cat QuickHeal) 11.00, Trend Micro AntiVirus 9.120.0.1004, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Trend Micro HouseCall 9.120.0.1004, and Emsisoft Anti-Malware 5.1.0.1 allows remote attackers to bypass malware detection via a CAB file with a modified cbCabinet field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
cat quick_heal 11.00
trendmicro housecall 9.120.0.1004
CVE-2012-1453 MEDIUM

The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Trend Micro AntiVirus 9.120.0.1004, McAfee Gateway (formerly Webwasher) 2010.1C, Emsisoft Anti-Malware 5.1.0.1, CA eTrust Vet Antivirus 36.1.8511, Antiy Labs AVL SDK 2.0.3.7, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, Rising Antivirus 22.83.00.03, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via a CAB file with a modified coffFiles field. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different CAB parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
antiy avl_sdk 2.0.3.7
rising-global rising_antivirus 22.83.00.03
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
pandasecurity panda_antivirus 10.0.2.7
sophos sophos_anti-virus 4.61.0
mcafee gateway 2010.1c
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
microsoft security_essentials 2.0
ca etrust_vet_antivirus 36.1.8511
drweb dr.web_antivirus 5.0.2.03300
CVE-2012-1456 MEDIUM

The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Panda Antivirus 10.0.2.7, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, and Trend Micro HouseCall 9.120.0.1004 allows remote attackers to bypass malware detection via a TAR file with an appended ZIP file. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
symantec endpoint_protection 11.0
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
jiangmin jiangmin_antivirus 13.0.900
aladdin esafe 7.0.17.0
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
avg avg_anti-virus 10.0.0.1190
pandasecurity panda_antivirus 10.0.2.7
sophos sophos_anti-virus 4.61.0
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
cat quick_heal 11.00
comodo comodo_antivirus 7424
CVE-2012-1457 MEDIUM

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
antiy avl_sdk 2.0.3.7
symantec endpoint_protection 11.0
jiangmin jiangmin_antivirus 13.0.900
pc_tools pc_tools_antivirus 7.0.3.5
avg avg_anti-virus 10.0.0.1190
avira antivir 7.11.1.163
alwil avast_antivirus 5.0.677.0
cat quick_heal 11.00
anti-virus vba32 3.12.14.2
microsoft security_essentials 2.0
clamav clamav 0.96.4
alwil avast_antivirus 4.8.1351.0
virusbuster virusbuster 13.6.151.0
eset nod32_antivirus 5795
norman norman_antivirus_&_antispyware 6.06.12
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
k7computing antivirus 9.77.3565
aladdin esafe 7.0.17.0
trendmicro housecall 9.120.0.1004
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
CVE-2012-1459 MEDIUM

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, nProtect Anti-Virus 2011-01-17.01, Panda Antivirus 10.0.2.7, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field corresponding to that entire entry, plus part of the header of the next entry. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
nprotect nprotect_antivirus 2011-01-17.01
antiy avl_sdk 2.0.3.7
ahnlab v3_internet_security 2011.01.18.00
symantec endpoint_protection 11.0
jiangmin jiangmin_antivirus 13.0.900
pc_tools pc_tools_antivirus 7.0.3.5
avg avg_anti-virus 10.0.0.1190
pandasecurity panda_antivirus 10.0.2.7
sophos sophos_anti-virus 4.61.0
avira antivir 7.11.1.163
alwil avast_antivirus 5.0.677.0
cat quick_heal 11.00
anti-virus vba32 3.12.14.2
microsoft security_essentials 2.0
clamav clamav 0.96.4
alwil avast_antivirus 4.8.1351.0
virusbuster virusbuster 13.6.151.0
eset nod32_antivirus 5795
f-secure f-secure_anti-virus 9.0.16160.0
norman norman_antivirus_&_antispyware 6.06.12
f-prot f-prot_antivirus 4.6.2.117
rising-global rising_antivirus 22.83.00.03
k7computing antivirus 9.77.3565
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
gdata-software g_data_antivirus 21
kaspersky kaspersky_anti-virus 7.0.0.125
comodo comodo_antivirus 7424
CVE-2012-1461 MEDIUM

The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, Sophos Anti-Virus 4.61.0, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, and VBA32 3.12.14.2 allows remote attackers to bypass malware detection via a .tar.gz file with multiple compressed streams. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different Gzip parser implementations.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro trend_micro_antivirus 9.120.0.1004
bitdefender bitdefender 7.2
authentium command_antivirus 5.2.11.5
eset nod32_antivirus 5795
f-secure f-secure_anti-virus 9.0.16160.0
norman norman_antivirus_&_antispyware 6.06.12
symantec endpoint_protection 11.0
rising-global rising_antivirus 22.83.00.03
k7computing antivirus 9.77.3565
jiangmin jiangmin_antivirus 13.0.900
fortinet fortinet_antivirus 4.2.254.0
trendmicro housecall 9.120.0.1004
avg avg_anti-virus 10.0.0.1190
sophos sophos_anti-virus 4.61.0
mcafee gateway 2010.1c
mcafee scan_engine 5.400.0.1158
ikarus ikarus_virus_utilities_t3_command_line_scanner 1.1.97.0
emsisoft anti-malware 5.1.0.1
kaspersky kaspersky_anti-virus 7.0.0.125
anti-virus vba32 3.12.14.2
CVE-2012-2995 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allow remote attackers to inject arbitrary web script or HTML via (1) the wrsApprovedURL parameter to addRuleAttrWrsApproveUrl.imss or (2) the src parameter to initUpdSchPage.imss.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
trendmicro interscan_messaging_security_suite 7.1
CVE-2012-2996 MEDIUM

Cross-site request forgery (CSRF) vulnerability in saveAccountSubTab.imss in Trend Micro InterScan Messaging Security Suite 7.1-Build_Win32_1394 allows remote attackers to hijack the authentication of administrators for requests that create admin accounts via a saveAuth action.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
trendmicro interscan_messaging_security_suite 7.1
CVE-2014-3922 MEDIUM

Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows remote authenticated users to inject arbitrary web script or HTML via the addWhiteListDomainStr parameter to addWhiteListDomain.imss.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
trendmicro interscan_messaging_security_virtual_appliance 8.5.1.1516
CVE-2014-8510 MEDIUM

The AdminUI in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) before 6.0 HF build 1244 allows remote authenticated users to read arbitrary files via vectors related to configuration input when saving filters.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
trendmicro interscan_web_security_virtual_appliance 6.0
trendmicro interscan_web_security_virtual_appliance 5.1
trendmicro interscan_web_security_virtual_appliance 5.6
trendmicro interscan_web_security_virtual_appliance 5.5
CVE-2014-9641 HIGH

The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x00222400 IOCTL call.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
trendmicro tmeext.sys *
CVE-2015-2872 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allow remote attackers to inject arbitrary web script or HTML via (1) crafted input to index.php that is processed by certain Internet Explorer 7 configurations or (2) crafted input to the widget feature.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
trendmicro deep_discovery_inspector 3.7
trendmicro deep_discovery_inspector 3.8
trendmicro deep_discovery_inspector 3.5
trendmicro deep_discovery_inspector 3.6
CVE-2015-2873 MEDIUM

Trend Micro Deep Discovery Inspector (DDI) on Deep Discovery Threat appliances with software before 3.5.1477, 3.6.x before 3.6.1217, 3.7.x before 3.7.1248, 3.8.x before 3.8.1263, and other versions allows remote attackers to obtain sensitive information or change the configuration via a direct request to the (1) system log URL, (2) whitelist URL, or (3) blacklist URL.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-425,

Products Affected

Vendor Product Version
trendmicro deep_discovery_inspector 3.7
trendmicro deep_discovery_inspector 3.8
trendmicro deep_discovery_inspector 3.5
trendmicro deep_discovery_inspector 3.6
CVE-2016-1223 MEDIUM

Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 3.9 1.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
trendmicro worry-free_business_security 9.0
trendmicro officescan 11.0
trendmicro worry-free_business_security_services 5.0
CVE-2016-1224 MEDIUM

CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
trendmicro worry-free_business_security 9.0
trendmicro worry-free_business_security_services 5.0
CVE-2016-1225 MEDIUM

Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
trendmicro internet_security 8.0
trendmicro internet_security 10.0
CVE-2016-1226 MEDIUM

Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
trendmicro internet_security 8.0
trendmicro internet_security 10.0
CVE-2016-3987 HIGH

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
trendmicro password_manager -
CVE-2016-4351 HIGH

SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
trendmicro email_encryption_gateway *