Home/Product/eset security
Product

eset security

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-3779
< 11.0.15004.0
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render E
6.1MEDIUM
CVE-2024-1619
>= 8.0 and <= 8.0.3.30
Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could pot
6.1MEDIUM
CVE-2024-0353
< 7.3.15006.0
Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files withou
7.8HIGH
CVE-2023-5594
all versions
Improper validation of the server’s certificate chain in secure traffic scanning feature considered intermediate certificate sig
7.5HIGH
CVE-2023-48795
all versions
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9MEDIUM
CVE-2023-3160
all versions
The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move fil
7.8HIGH
CVE-2022-37348
<= 17.7.1383
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
5.5MEDIUM
CVE-2022-37347
<= 17.7.1383
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
5.5MEDIUM
CVE-2022-34893
<= 17.7.1179
Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could manipulate a
7.8HIGH
CVE-2022-29489
<= 1.8.33
Cross-Site Request Forgery (CSRF) vulnerability in Sucuri Security plugin <= 1.8.33 at WordPress leading to Event log entry creati
4.3MEDIUM
CVE-2022-35234
all versions
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that cou
7.1HIGH
CVE-2022-30703
all versions
Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attac
7.8HIGH
CVE-2022-30702
all versions
Trend Micro Security 2022 and 2021 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure vulnerability that cou
5.5MEDIUM
CVE-2021-37851
>= 6.0 and < 8.0.15009.0
Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the
7.3HIGH
CVE-2022-27167
>= 6.0 and < 8.0.15009.0
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" f
7.1HIGH
CVE-2021-37852
>= 7.0.15008.0 and <= 8.0.15004.0
ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to esca
7.8HIGH
CVE-2020-26941
<= 7.2
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (delet
5.5MEDIUM
CVE-2019-14688
all versions
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package
7.0HIGH
CVE-2018-12636
< 7.0.3
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileg
7.2HIGH
CVE-2018-7433
<= 6.9.0
The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.
7.5HIGH
CVE-2018-6218
all versions
A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a v
7.0HIGH
CVE-2005-1239
all versions
Directory traversal vulnerability in the third party tool from Raz-Lee, as used to secure the iSeries AS/400 FTP server, allows re
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin