Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2015-2760

Published Mar 27, 2015

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated u…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-2759

Published Mar 27, 2015

Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remot…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2758

Published Mar 27, 2015

The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2757

Published Mar 27, 2015

The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2053

Published Feb 23, 2015

The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1619

Published Feb 17, 2015

Cross-site scripting (XSS) vulnerability in the Secure Web Mail Client user interface in McAfee Email Gateway (MEG) 7.6.x before 7.6.3.2, 7.5.x before 75.6, 7.0.x through 7.0.5, 5…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1618

Published Feb 17, 2015

The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1617

Published Feb 17, 2015

Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary w…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1616

Published Feb 17, 2015

SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL comma…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0922

Published Jan 9, 2015

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the admini…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0921

Published Jan 9, 2015

XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arb…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8535

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8534

Published Oct 29, 2014

Unspecified vulnerability in the login form in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to cause a denial of service via a crafted value in the d…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8533

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8532

Published Oct 29, 2014

Unspecified vulnerability in McAfee Network Data Loss Prevention before (NDLP) before 9.3 allows local users to obtain sensitive information and impact integrity via unknown vecto…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8531

Published Oct 29, 2014

The TLS/SSL Server in McAfee Network Data Loss Prevention (NDLP) before 9.3 uses weak cipher algorithms, which makes it easier for remote authenticated users to execute arbitrary…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8530

Published Oct 29, 2014

Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect integrity, or cause a denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8529

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8528

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8527

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password."

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8525

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 599 CVEsPage 18 of 24