Vulnerabilities > Trend Micro > Officescan Corporate Edition > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-03-17 CVE-2008-1366 Improper Input Validation vulnerability in Trend Micro Officescan Corporate Edition
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers a NULL pointer dereference.
network
low complexity
trend-micro CWE-20
5.0
2008-03-17 CVE-2008-1365 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Trend Micro Officescan Corporate Edition
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.
network
low complexity
trend-micro CWE-119
6.4
2006-10-10 CVE-2006-5211 Unspecified vulnerability in Trend Micro Officescan Corporate Edition 6.5/7.0/7.3
Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to remove OfficeScan clients via a certain HTTP request that invokes the OfficeScan CGI program.
network
low complexity
trend-micro
6.4