Vulnerabilities > Trendmicro

DATE CVE VULNERABILITY TITLE RISK
2020-10-14 CVE-2020-25778 Information Exposure Through an Error Message vulnerability in Trendmicro Antivirus 2019/2020
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could supply a kernel pointer and leak several bytes of memory.
local
low complexity
trendmicro CWE-209
6.0
2020-10-14 CVE-2020-25777 Unspecified vulnerability in Trendmicro Antivirus 2019/2020
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass the Web Threat Protection feature of the product.
network
low complexity
trendmicro
5.4
2020-10-13 CVE-2020-25779 Unspecified vulnerability in Trendmicro Antivirus 2020
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in which a Internationalized Domain Name homograph attack (Puny-code) could be used to add a malicious website to the approved websites list of Trend Micro Antivirus for Mac to bypass the web threat protection feature.
local
low complexity
trendmicro
3.3
2020-10-02 CVE-2020-25776 Link Following vulnerability in Trendmicro Antivirus 2019/2020
Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges.
local
low complexity
trendmicro CWE-59
7.8
2020-09-29 CVE-2020-25775 Race Condition vulnerability in Trendmicro products
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
local
high complexity
trendmicro CWE-362
6.3
2020-09-29 CVE-2020-25774 Out-of-bounds Read vulnerability in Trendmicro Apex ONE 2019/Saas
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account.
network
low complexity
trendmicro CWE-125
4.3
2020-09-29 CVE-2020-25773 Double Free vulnerability in Trendmicro Apex ONE 2019/Saas
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products.
local
low complexity
trendmicro CWE-415
7.8
2020-09-29 CVE-2020-25772 Out-of-bounds Read vulnerability in Trendmicro Apex ONE 2019/Saas
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.
local
low complexity
trendmicro CWE-125
5.5
2020-09-29 CVE-2020-25771 Out-of-bounds Read vulnerability in Trendmicro Apex ONE 2019/Saas
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.
local
low complexity
trendmicro CWE-125
5.5
2020-09-29 CVE-2020-25770 Out-of-bounds Read vulnerability in Trendmicro Apex ONE 2019/Saas
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product.
local
low complexity
trendmicro CWE-125
5.5