Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Loss Prevention Endpoint MEDIUM 6.8
CVE-2015-2759

Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hot…

Fix: after 9.3.400
Fix from $1,600 2015-03-27
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2015-2758

The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain…

Fix: after 9.3.400
Fix from $1,600 2015-03-27
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2015-1616

SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users …

Fix: after 9.3.300
Fix from $1,600 2015-02-17
Data Loss Prevention Endpoint MEDIUM 6.9
CVE-2015-1305

McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privilege…

Fix: after 9.3.300
Fix from $1,600 2015-02-06
Epolicy Orchestrator MEDIUM 5.0
CVE-2015-0922EPSS 13%

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows …

Fix: after 4.6.8
Fix from $1,600 2015-01-09
Network Data Loss Prevention HIGH 7.5
CVE-2014-8533

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.

Fix: after 9.2.2
Fix from $1,950 2014-10-29
Network Data Loss Prevention HIGH 7.5
CVE-2014-8522

The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers t…

Fix: after 9.2.2
Fix from $1,950 2014-10-29
Network Data Loss Prevention HIGH 7.5
CVE-2014-8530

Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect in…

Fix: after 9.2.2
Fix from $1,950 2014-10-29
Network Data Loss Prevention MEDIUM 6.8
CVE-2014-8523

Cross-site request forgery (CSRF) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to hijack the authen…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 6.5
CVE-2014-8531

The TLS/SSL Server in McAfee Network Data Loss Prevention (NDLP) before 9.3 uses weak cipher algorithms, which makes it easier for remote authenticat…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8520

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network por…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8524

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remot…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8525

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes i…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Security Manager MEDIUM 6.8
CVE-2014-2390

Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x befor…

Fix: 6.1.15.39 / 7.1.5.15+
Fix from $1,600 2014-08-29
Asset Manager MEDIUM 6.5
CVE-2014-2587

SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL co…

No fix yet
Fix from $1,600 2014-03-24
Epolicy Orchestrator MEDIUM 6.3
CVE-2014-2205

The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to…

Fix: after 4.6.7
Fix from $1,600 2014-02-26
Vulnerability Manager MEDIUM 6.8
CVE-2014-1473

Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow re…

Fix: after 7.5.5
Fix from $1,600 2014-01-16
Email Gateway HIGH 9.0
CVE-2013-7103

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in …

No fix yet
Fix from $1,950 2013-12-14
Email Gateway HIGH 9.0
CVE-2013-7104

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) …

No fix yet
Fix from $1,950 2013-12-14
Email Gateway MEDIUM 6.5
CVE-2013-7092

Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbi…

No fix yet
Fix from $1,600 2013-12-13
Email Gateway HIGH 8.5
CVE-2013-6349

McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect…

Mitigation only
Fix from $1,950 2013-11-02
Agent MEDIUM 5.0
CVE-2013-3627

FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to …

Fix: 4.5.0.1927 / 4.6.0.3258+
Fix from $1,600 2013-10-05
Epolicy Orchestrator MEDIUM 6.5
CVE-2013-4882

Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agen…

Fix: after 4.6.6
Fix from $1,600 2013-07-22
Epolicy Orchestrator HIGH 7.9
CVE-2013-0140

SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote att…

Fix: after 4.5.6
Fix from $1,950 2013-05-01
Mcafee Virtual Technician HIGH 8.2
CVE-2012-5879EPSS 5%

An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cr…

Fix: after 6.5.0.2101
Fix from $1,950 2013-03-28
Email And Web Security HIGH 7.8
CVE-2012-4014

Unspecified vulnerability in McAfee Email Anti-virus (formerly WebShield SMTP) allows remote attackers to cause a denial of service via unknown vecto…

No fix yet
Fix from $1,950 2012-09-25
Total Protection 2010 MEDIUM 6.2
CVE-2010-5166

Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous c…

Mitigation only
Fix from $1,600 2012-08-25
Smartfilter Administration HIGH 10.0
CVE-2012-4599

McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBo…

Fix: after 4.2.1
Fix from $1,950 2012-08-22
Mcafee Virtual Technician HIGH 9.3
CVE-2012-4598EPSS 29%

An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause…

Fix: after 6.3.0.1911
Fix from $1,950 2012-08-22
Email And Web Security HIGH 7.5
CVE-2012-4595

McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack…

Mitigation only
Fix from $1,950 2012-08-22