Vulnerabilities > Trend Micro > Officescan > 7.3

DATE CVE VULNERABILITY TITLE RISK
2008-10-23 CVE-2008-3862 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Trend Micro Officescan 7.3/8.0
Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to "parsing CGI requests."
network
low complexity
trend-micro CWE-119
critical
10.0
2008-10-03 CVE-2008-2439 Path Traversal vulnerability in Trend Micro Officescan and Worry Free Business Security
Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business Security 5.0 before build 1220 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP request.
network
low complexity
trend-micro CWE-22
5.0
2008-09-16 CVE-2008-2437 Buffer Errors vulnerability in Trend Micro Client-Server-Messaging Security and Officescan
Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter.
network
low complexity
trend-micro CWE-119
critical
10.0
2008-07-30 CVE-2008-3364 Buffer Errors vulnerability in Trend Micro Officescan 7.3
Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and Worry-Free Business Security (WFBS) 5.0 allows remote attackers to execute arbitrary code via a long string in the Server property, and possibly other properties.
network
trend-micro CWE-119
critical
9.3
2007-06-27 CVE-2007-3454 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Trend Micro Officescan 7.3/8.0
Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library.
network
low complexity
trend-micro CWE-119
critical
10.0
2007-02-08 CVE-2007-0851 Buffer Overflow vulnerability in Trend Micro Antivirus UPX Compressed PE File
Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable.
network
trend-micro
critical
9.3
2006-12-11 CVE-2006-6458 Remote Denial Of Service vulnerability in Trend Micro products
The Trend Micro scan engine before 8.320 for Windows and before 8.150 on HP-UX and AIX, as used in Trend Micro PC Cillin - Internet Security 2006, Office Scan 7.3, and Server Protect 5.58, allows remote attackers to cause a denial of service (CPU consumption and system hang) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero, which triggers an infinite loop.
network
low complexity
trend-micro
7.8
2006-11-30 CVE-2006-6179 Buffer Overflow vulnerability in Trend Micro Officescan 7.3
Buffer overflow in PCCSRV\Web_console\RemoteInstallCGI\CgiRemoteInstall.exe for Trend Micro OfficeScan 7.3 before build 7.3.0.1089 allows remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
trend-micro
7.5
2006-11-30 CVE-2006-6178 Buffer Overflow vulnerability in Trend Micro Officescan 7.3
Buffer overflow in PCCSRV\Web_console\RemoteInstallCGI\Wizard.exe for Trend Micro OfficeScan 7.3 before build 7.3.0.1087 allows remote attackers to execute arbitrary code via unknown attack vectors.
network
low complexity
trend-micro
7.5