Trend Micro / Control Manager
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-25252 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-se… | MEDIUM | 5.5 | Mar 3, 2021 |
| CVE-2019-14688 | Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnera… | HIGH | 7.0 | Feb 20, 2020 |
| CVE-2018-10512 | A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, w… | HIGH | 7.5 | Aug 15, 2018 |
| CVE-2018-10511 | A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to conduct a server-side request forgery (SSRF) attack on vulnera… | CRITICAL | 10.0 | Aug 15, 2018 |
| CVE-2018-10510 | A Directory Traversal Remote Code Execution vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to execute arbitrary co… | CRITICAL | 9.8 | Aug 15, 2018 |
| CVE-2018-3607 | XXXTreeNode method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitr… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3606 | XXXStatusXXX, XXXSummary, TemplateXXX and XXXCompliance method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 cou… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3605 | TopXXX, ViolationXXX, and IncidentXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3604 | GetXXX method SQL injection remote code execution (RCE) vulnerabilities in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary c… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3603 | A CGGIServlet SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arbitrary cod… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3602 | An AdHocQuery_Processor SQL injection remote code execution (RCE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to execute arb… | HIGH | 8.8 | Feb 9, 2018 |
| CVE-2018-3601 | A password hash usage authentication bypass vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to bypass authentication on vulnerab… | CRITICAL | 9.8 | Feb 9, 2018 |
| CVE-2018-3600 | A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose sensitive… | MEDIUM | 6.5 | Feb 9, 2018 |
| CVE-2016-6220 | Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0. | HIGH | 7.5 | Aug 7, 2017 |
| CVE-2017-11390 | XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-470… | HIGH | 7.5 | Aug 2, 2017 |
| CVE-2017-11389 | Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing dir… | CRITICAL | 9.8 | Aug 2, 2017 |
| CVE-2017-11388 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided string… | HIGH | 8.8 | Aug 2, 2017 |
| CVE-2017-11387 | Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can ch… | HIGH | 7.5 | Aug 2, 2017 |
| CVE-2017-11386 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHa… | CRITICAL | 9.8 | Aug 2, 2017 |
| CVE-2017-11385 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHa… | CRITICAL | 9.8 | Aug 2, 2017 |
| CVE-2017-11384 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHan… | CRITICAL | 9.8 | Aug 2, 2017 |
| CVE-2017-11383 | SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHa… | CRITICAL | 9.8 | Aug 2, 2017 |
| CVE-2012-2998 | SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attacker… | HIGH | 7.5 | Sep 28, 2012 |
| CVE-2011-5001 | Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5… | HIGH | 10.0 | Dec 25, 2011 |
| CVE-2007-0851 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) C… | HIGH | 9.3 | Feb 8, 2007 |
Showing 1 to 25 of 28 CVEs