Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2016-1834

Published May 20, 2016

Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1,…

CVSS 7.8 · High

CVE-2016-1833

Published May 20, 2016

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers…

CVSS 5.5 · Medium

CVE-2016-4535

Published May 5, 2016

Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3983

Published Apr 8, 2016

McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3969

Published Apr 6, 2016

Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2199

Published Feb 1, 2016

Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8773

Published Jan 29, 2016

Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers to cause a denial of service (system crash) via a long vau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8772

Published Jan 29, 2016

McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-8765

Published Jan 8, 2016

Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitr…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8577

Published Dec 16, 2015

The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresse…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-8024

Published Dec 2, 2015

McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-7612

Published Oct 1, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations page in Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.9 and earlier allow remote att…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7238

Published Sep 18, 2015

The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-7237

Published Sep 18, 2015

Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows remote attackers to obtain sensitive information via unspeci…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2859

Published Jun 23, 2015

Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X.509 certificates from SSL ser…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4559

Published Jun 15, 2015

Cross-site scripting (XSS) vulnerability in the product deployment feature in the Java core web services in Intel McAfee ePolicy Orchestrator (ePO) before 5.1.2 allows remote atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3987

Published May 14, 2015

Multiple unquoted Windows search path vulnerabilities in the (1) Client Management and (2) Gateway in McAfee ePO Deep Command 2.1 and 2.2 before HF 1058831 allow local users to ga…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3030

Published Apr 8, 2015

The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to obtain sensitive configuration information via unspecified vectors.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3029

Published Apr 8, 2015

The web interface in McAfee Advanced Threat Defense (MATD) before 3.4.4.63 does not properly restrict access, which allows remote authenticated users to obtain sensitive informati…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3028

Published Apr 8, 2015

McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configuration settings via crafted par…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 599 CVEsPage 17 of 24