Vulnerabilities > Trendmicro
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-07-29 | CVE-2021-36741 | Unrestricted Upload of File with Dangerous Type vulnerability in Trendmicro products An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. | 8.8 |
2021-07-29 | CVE-2021-36742 | Improper Input Validation vulnerability in Trendmicro products A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. | 7.8 |
2021-07-20 | CVE-2021-32463 | Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE and Worry-Free Business Security An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on affected installations. | 7.8 |
2021-07-08 | CVE-2021-32461 | Incorrect Conversion between Numeric Types vulnerability in Trendmicro Password Manager Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. | 7.8 |
2021-07-08 | CVE-2021-32462 | Unspecified vulnerability in Trendmicro Password Manager Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. | 8.8 |
2021-06-17 | CVE-2021-31521 | Cross-site Scripting vulnerability in Trendmicro Interscan web Security Virtual Appliance 6.5 Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in the product's Captive Portal. | 5.4 |
2021-06-03 | CVE-2021-32460 | Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Maximum Security 2021 17.0 The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. | 7.8 |
2021-05-27 | CVE-2021-32458 | Out-of-bounds Write vulnerability in Trendmicro Home Network Security Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. | 7.8 |
2021-05-27 | CVE-2021-32459 | Use of Hard-coded Credentials vulnerability in Trendmicro Home Network Security Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. | 6.5 |
2021-05-26 | CVE-2021-32457 | Out-of-bounds Write vulnerability in Trendmicro Home Network Security 6.1.567/6.6.604 Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. | 7.8 |