Trend Micro Officescan Corporate Edition vulnerabilities
4 known vulnerabilities affecting trend_micro/officescan_corporate_edition.
Total CVEs
4
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2008-1365MEDIUMCVSS 6.4PoC≤ 7.3_patch3_build1314≤ 8.0_patch2_build11892008-03-17
CVE-2008-1365 [MEDIUM] CWE-119 CVE-2008-1365: Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and e
Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachab
nvd
CVE-2008-1366MEDIUMCVSS 5.0≤ 7.3_patch3_build1314≤ 8.0_patch2_build11892008-03-17
CVE-2008-1366 [MEDIUM] CWE-20 CVE-2008-1366: Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1
Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers a NULL pointer dereference.
nvd
CVE-2007-0325CRITICALCVSS 9.3PoCv7.0v7.32007-02-20
CVE-2007-0325 [CRITICAL] CWE-119 CVE-2007-0325: Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code via a crafted HTML document.
nvd
CVE-2006-5211MEDIUMCVSS 6.4v6.5v7.0+1 more2006-10-10
CVE-2006-5211 [MEDIUM] CVE-2006-5211: Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and
Trend Micro OfficeScan 6.0 in Client/Server/Messaging (CSM) Suite for SMB 2.0 before 6.0.0.1385, and OfficeScan Corporate Edition (OSCE) 6.5 before 6.5.0.1418, 7.0 before 7.0.0.1257, and 7.3 before 7.3.0.1053 allow remote attackers to remove OfficeScan clients via a certain HTTP request that invokes the OfficeScan CGI program.
nvd