Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2018-6687

Published Feb 21, 2019

Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3610

Published Feb 13, 2019

Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3604

Published Feb 1, 2019

Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session v…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3593

Published Jan 28, 2019

Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3587

Published Jan 23, 2019

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution f…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3584

Published Jan 23, 2019

Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> admin…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3581

Published Jan 9, 2019

Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6668

Published Dec 31, 2018

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DLL through interpreters such as…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6669

Published Dec 20, 2018

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6707

Published Dec 14, 2018

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, une…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-6706

Published Dec 12, 2018

Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6705

Published Dec 12, 2018

Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific cond…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6704

Published Dec 12, 2018

Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific cond…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6703

Published Dec 11, 2018

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-6757

Published Dec 6, 2018

Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted mal…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6756

Published Dec 6, 2018

Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially craf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6755

Published Dec 6, 2018

Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6695

Published Oct 3, 2018

SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to sp…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6689

Published Oct 3, 2018

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6700

Published Sep 24, 2018

DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local users to execute arbitrary code via specially crafted malw…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6682

Published Sep 24, 2018

Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 599 CVEsPage 12 of 24