Vulnerabilities > Trend Micro > Client Server Messaging Security > 3.5

DATE CVE VULNERABILITY TITLE RISK
2008-09-16 CVE-2008-2437 Buffer Errors vulnerability in Trend Micro Client-Server-Messaging Security and Officescan
Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.
network
low complexity
trend-micro CWE-119
critical
10.0
2007-02-08 CVE-2007-0856 Local Privilege Escalation vulnerability in Trend Micro AntiVirus Scan Engine TMComm
TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server / Messaging Security for SMB 3.5, Damage Cleanup Services 3.2, and possibly other products, assigns Everyone write permission for the \\.\TmComm DOS device interface, which allows local users to access privileged IOCTLs and execute arbitrary code or overwrite arbitrary memory in the kernel context.
local
low complexity
trend-micro
7.2