Trend Micro

    Dashboard / Vendors

    Products: 53
    Vulnerabilities: 108
    Known Exploited: 0
    37
    Critical Level Threats
    31
    High Level Threats
    39
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2016-5840

    hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

    Last Modified: Apr 12, 2025
    Published: Jun 30, 2016

    CVE-2016-3664

    Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.

    Last Modified: Apr 12, 2025
    Published: May 23, 2016

    CVE-2015-3326

    Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predictable values, which makes it easier for remote attackers to bypass authentication via a brute force attack.

    Last Modified: Apr 12, 2025
    Published: May 14, 2015

    CVE-2012-2998

    SQL injection vulnerability in the ad hoc query module in Trend Micro Control Manager (TMCM) before 5.5.0.1823 and 6.0 before 6.0.0.1449 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Last Modified: Apr 11, 2025
    Published: Sep 28, 2012

    CVE-2011-5001

    Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcessor.exe in Trend Micro Control Manager 5.5 before Build 1613 allows remote attackers to execute arbitrary code via a crafted IPC packet to TCP port 20101.

    Last Modified: Apr 11, 2025
    Published: Dec 25, 2011
    Items Per Page
    Trend_Micro Vulnerabilities & Security CVEs | CVE-DB