Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2017-4013

Published May 17, 2017

Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4012

Published May 17, 2017

Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modific…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-4011

Published May 17, 2017

Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information vi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8030

Published Apr 25, 2017

A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows remote attackers to create a Denial of Service on the acti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8032

Published Mar 31, 2017

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8031

Published Mar 28, 2017

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input fil…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3899

Published Mar 14, 2017

SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain product information via a crafted H…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8027

Published Mar 14, 2017

SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, whi…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8026

Published Mar 14, 2017

Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspeci…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8025

Published Mar 14, 2017

SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted H…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8024

Published Mar 14, 2017

Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8023

Published Mar 14, 2017

Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to byp…

CVSS 8.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-8022

Published Mar 14, 2017

Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-8021

Published Mar 14, 2017

Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof u…

CVSS 5.0 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-8020

Published Mar 14, 2017

Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary…

CVSS 8.0 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-8019

Published Mar 14, 2017

Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject ar…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8018

Published Mar 14, 2017

Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthoriz…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8017

Published Mar 14, 2017

Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserve…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8016

Published Mar 14, 2017

Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-8012

Published Mar 14, 2017

Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject ho…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8009

Published Mar 14, 2017

Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unaut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8007

Published Mar 14, 2017

Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry key…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8005

Published Mar 14, 2017

File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 599 CVEsPage 15 of 24