Skip to main content

Vendor archive

mcafee CVEs

Beta · best-effort

599 CVEs tagged to vendor mcafee34 Critical, 202 High, 305 Medium, 58 Low, 0 Unrated.

CVE-2019-3670

Published Feb 24, 2020

Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote unauthenticated attacker to execute arbitrary code via a cr…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7251

Published Feb 14, 2020

Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security fe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3667

Published Dec 11, 2019

DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folde…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3666

Published Dec 3, 2019

API Abuse/Misuse vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to navigate to restric…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3665

Published Dec 3, 2019

Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website whic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3654

Published Nov 22, 2019

Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3663

Published Nov 14, 2019

Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-3662

Published Nov 14, 2019

Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to file…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3661

Published Nov 14, 2019

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to e…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3640

Published Nov 14, 2019

Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login detai…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3660

Published Nov 13, 2019

Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via c…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3651

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3650

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3649

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3641

Published Nov 13, 2019

Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify sto…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3636

Published Oct 28, 2019

A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 201-225 of 599 CVEsPage 9 of 24