9.8
CVE-2019-18190
- EPSS 0.73%
- Published 09.12.2019 19:15:14
- Last modified 21.11.2024 04:32:47
- Source security@trendmicro.com
- Teams watchlist Login
- Open Login
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
Data is provided by the National Vulnerability Database (NVD)
Trendmicro ≫ Antivirus+ Security 2020 Version >= 16.0 < 16.0.1227
Trendmicro ≫ Internet Security 2020 Version >= 16.0 < 16.0.1227
Trendmicro ≫ Maximum Security 2020 Version >= 16.0 < 16.0.1227
Trendmicro ≫ Premium Security 2020 Version >= 16.0 < 16.0.1227
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.73% | 0.715 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.