Vulnerabilities > Trendmicro > Deep Discovery Inspector

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-46902 SQL Injection vulnerability in Trendmicro Deep Discovery Inspector 6.6/6.7
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute high-privileged code (admin user rights) on the target system in order to exploit this vulnerability.
network
low complexity
trendmicro CWE-89
critical
9.1
2024-10-22 CVE-2024-46903 Unspecified vulnerability in Trendmicro Deep Discovery Inspector 6.6/6.7
A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
network
low complexity
trendmicro
6.5
2021-03-03 CVE-2021-25252 Resource Exhaustion vulnerability in Trendmicro products
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
local
low complexity
trendmicro CWE-400
5.5
2018-09-28 CVE-2018-15365 Cross-site Scripting vulnerability in Trendmicro Deep Discovery Inspector
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations.
network
low complexity
trendmicro CWE-79
5.4