Vulnerabilities > Trendmicro > Scanmail > 12.0

DATE CVE VULNERABILITY TITLE RISK
2017-12-16 CVE-2017-14093 Cross-site Scripting vulnerability in Trendmicro Scanmail 12.0
The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.
network
trendmicro CWE-79
4.3
2017-12-16 CVE-2017-14092 Cross-Site Request Forgery (CSRF) vulnerability in Trendmicro Scanmail 12.0
The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.
6.8
2017-12-16 CVE-2017-14091 Insufficient Verification of Data Authenticity vulnerability in Trendmicro Scanmail 12.0
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.
network
high complexity
trendmicro CWE-345
7.6
2017-12-16 CVE-2017-14090 Inadequate Encryption Strength vulnerability in Trendmicro Scanmail 12.0
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
network
low complexity
trendmicro CWE-326
6.4