Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Mobility Manager MEDIUM 5.0
CVE-2012-4591

About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, wh…

Fix: after 9.6
Fix from $1,600 2012-08-22
Enterprise Mobility Manager MEDIUM 5.0
CVE-2012-4592

The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, w…

Fix: after 9.6
Fix from $1,600 2012-08-22
Application Control MEDIUM 5.0
CVE-2012-4593

McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attribu…

Mitigation only
Fix from $1,600 2012-08-22
Firewall Reporter HIGH 7.5
CVE-2011-5100

The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obt…

Fix: after 5.1.0.6
Fix from $1,950 2012-08-22
Email And Web Security MEDIUM 6.8
CVE-2012-4581

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl…

Mitigation only
Fix from $1,600 2012-08-22
Saas Endpoint Protection MEDIUM 5.0
CVE-2011-5101

The Rumor technology in McAfee SaaS Endpoint Protection before 5.2.4 allows remote attackers to relay e-mail messages via unspecified vectors, as dem…

Fix: after 5.2.3
Fix from $1,600 2012-08-22
Virusscan Enterprise HIGH 9.3
CVE-2009-5118

Untrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an uns…

Fix: after 8.5i
Fix from $1,950 2012-08-22
Common Management Agent MEDIUM 6.5
CVE-2009-5115

McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenti…

Mitigation only
Fix from $1,600 2012-08-22
Linuxshield MEDIUM 6.5
CVE-2009-5116

McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin acces…

Fix: after 1.5.1
Fix from $1,600 2012-08-22
Virusscan Enterprise MEDIUM 6.4
CVE-2010-3496

McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, whi…

No fix yet
Fix from $1,600 2012-08-22
Web Gateway MEDIUM 5.0
CVE-2012-2212

McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname i…

Mitigation only
Fix from $1,600 2012-04-28
Saas Endpoint Protection MEDIUM 6.8
CVE-2011-3006

The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyAS…

Fix: after 5.2.1
Fix from $1,600 2011-08-10
Saas Endpoint Protection MEDIUM 6.8
CVE-2011-3007

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files …

Fix: after 5.2.1
Fix from $1,600 2011-08-10
Email Gateway MEDIUM 6.5
CVE-2010-2116

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privi…

No fix yet
Fix from $1,600 2010-05-28
Email And Web Security Appliance HIGH 7.8
CVE-2009-3339

Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors,…

No fix yet
Fix from $1,950 2009-09-24
Groupshield HIGH 9.3
CVE-2009-1491

McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, …

No fix yet
Fix from $1,950 2009-05-05
Active Virus Defense HIGH 7.6
CVE-2009-1348

The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microso…

Patch available
Fix from $1,950 2009-04-30
Encrypted Usb Manager MEDIUM 6.8
CVE-2008-3605

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to con…

Patch available
Fix from $1,600 2008-08-12
Cma MEDIUM 5.0
CVE-2008-1855EPSS 8%

FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot…

Fix: after 3.6.0.574
Fix from $1,600 2008-04-16
Agent MEDIUM 5.4
CVE-2008-1357EPSS 6%

Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used …

No fix yet
Fix from $1,600 2008-03-17
E Business Server HIGH 8.8
CVE-2008-0127EPSS 9%

The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute a…

Fix: after 8.5.2
Fix from $1,950 2008-01-10
E Business Server HIGH 9.3
CVE-2007-2957EPSS 6%

Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute…

Fix: after 8.5.2
Fix from $1,950 2007-10-31
E Business Server HIGH 7.6
CVE-2006-5271

Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and ea…

Mitigation only
Fix from $1,950 2007-07-12
Common Management Agent HIGH 7.6
CVE-2006-5273EPSS 6%

Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.4…

Fix: after 3.6.0.453
Fix from $1,950 2007-07-12
Common Management Agent HIGH 7.6
CVE-2006-5274

Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows …

Patch available
Fix from $1,950 2007-07-12
Common Management Agent HIGH 7.5
CVE-2006-5272

Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.…

Fix: after 3.6.0.453
Fix from $1,950 2007-07-12
Security Center HIGH 10.0
CVE-2007-2584EPSS 10%

Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCent…

Patch available
Fix from $1,950 2007-05-10
Virusscan Enterprise HIGH 7.9
CVE-2007-2152

Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitra…

Fix: after 8.0i
Fix from $1,950 2007-04-19
E Business Server MEDIUM 5.0
CVE-2007-2151

The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (servi…

Patch available
Fix from $1,600 2007-04-19
Virusscan Enterprise HIGH 7.5
CVE-2007-1538

McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password pr…

Mitigation only
Fix from $1,950 2007-03-20