Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Epolicy Orchestrator HIGH 9.3
CVE-2007-1498EPSS 8%

Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy …

Patch available
Fix from $1,950 2007-03-16
Virex MEDIUM 6.6
CVE-2007-1227

VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack o…

Fix: after 7.7
Fix from $1,600 2007-03-02
Neotrace HIGH 7.5
CVE-2006-6707EPSS 56%

Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrace Pro (…

Mitigation only
Fix from $1,950 2006-12-23
Internet Security Suite MEDIUM 5.0
CVE-2006-5417

McAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus,…

No fix yet
Fix from $1,600 2006-10-20
Epolicy Orchestrator HIGH 10.0
CVE-2006-5156EPSS 72%

Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary cod…

Patch available
Fix from $1,950 2006-10-05
Antispyware MEDIUM 6.8
CVE-2006-3961EPSS 34%

Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network S…

Patch available
Fix from $1,600 2006-08-01
Epolicy Orchestrator Agent MEDIUM 5.0
CVE-2006-3623

Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to …

Fix: after 3.5.0
Fix from $1,600 2006-07-18
Webshield Smtp HIGH 10.0
CVE-2006-0559EPSS 6%

Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format …

Fix: after 4.5
Fix from $1,950 2006-04-04
Virex MEDIUM 5.0
CVE-2006-0982

The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web b…

Mitigation only
Fix from $1,600 2006-03-03
Common Management Agent HIGH 7.2
CVE-2005-4505

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privi…

No fix yet
Fix from $1,950 2005-12-23
Mcinsctl.dll MEDIUM 5.0
CVE-2005-3657

The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required do…

Mitigation only
Fix from $1,600 2005-12-21
Internet Security Suite MEDIUM 5.1
CVE-2005-3377

Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch …

Mitigation only
Fix from $1,600 2005-10-30
Intrushield Security Management System HIGH 7.5
CVE-2005-2188

McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possib…

Mitigation only
Fix from $1,950 2005-07-11
Antivirus Engine HIGH 7.5
CVE-2005-0643EPSS 10%

Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.

No fix yet
Fix from $1,950 2005-05-02
Antivirus Engine HIGH 7.5
CVE-2005-0644EPSS 7%

Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file wi…

No fix yet
Fix from $1,950 2005-05-02
Internet Security Suite HIGH 7.2
CVE-2005-1107

McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection…

Mitigation only
Fix from $1,950 2005-04-18
Security Installer Control System HIGH 7.5
CVE-2004-2635

An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that us…

Patch available
Fix from $1,950 2004-12-31
Freescan MEDIUM 5.0
CVE-2004-1908

McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via the GetSpecialFolderLocation …

No fix yet
Fix from $1,600 2004-12-31
Virusscan HIGH 7.2
CVE-2004-0831

McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray …

Patch available
Fix from $1,950 2004-09-14
Epolicy Orchestrator HIGH 7.5
CVE-2004-0038

McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST req…

Patch available
Fix from $1,950 2004-06-14
Epolicy Orchestrator MEDIUM 5.0
CVE-2004-0095EPSS 38%

McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary …

No fix yet
Fix from $1,600 2004-02-17
Epolicy Orchestrator HIGH 7.5
CVE-2003-0149

Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a P…

Patch available
Fix from $1,950 2003-08-27
Epolicy Orchestrator HIGH 7.5
CVE-2003-0616

Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2003-08-27
Epolicy Orchestrator HIGH 7.2
CVE-2003-0148

The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps tha…

Patch available
Fix from $1,950 2003-08-27
Epolicy Orchestrator MEDIUM 5.0
CVE-2003-0610

Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP…

Patch available
Fix from $1,600 2003-08-27
Epolicy Orchestrator HIGH 10.0
CVE-2002-0690EPSS 8%

Format string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET req…

Patch available
Fix from $1,950 2003-04-11
Virusscan MEDIUM 6.9
CVE-2002-2282

McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the …

Mitigation only
Fix from $1,600 2002-12-31
Webshield Smtp HIGH 7.5
CVE-2001-1456EPSS 6%

Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code v…

Patch available
Fix from $1,950 2001-09-04
Remote Desktop 32 MEDIUM 5.0
CVE-2001-0612

McAfee Remote Desktop 3.0 and earlier allows remote attackers to cause a denial of service (crash) via a large number of packets to port 5045.

Fix: after 3.0
Fix from $1,600 2001-08-22
Asap Virusscan MEDIUM 5.0
CVE-2001-1144EPSS 6%

Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP r…

Mitigation only
Fix from $1,600 2001-07-11