Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Security HIGH 7.8
CVE-2019-3582

Privilege Escalation vulnerability in Microsoft Windows client in McAfee Endpoint Security (ENS) 10.6.1 and earlier allows local users to gain elevat…

Fix: after 10.6.1
Fix from $1,950 2019-02-28
Agent HIGH 7.5
CVE-2019-3599

Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to…

Fix: after 5.5.2
Fix from $1,950 2019-02-28
Agent MEDIUM 5.3
CVE-2019-3598

Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via s…

Fix: after 5.5.2
Fix from $1,600 2019-02-28
Getsusp MEDIUM 5.5
CVE-2018-6687

Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp sca…

Fix: after 3.0.0.461
Fix from $1,600 2019-02-21
True Key MEDIUM 5.5
CVE-2019-3610

Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidenti…

Fix: after 3.1.9211.0
Fix from $1,600 2019-02-13
Epolicy Orchestrator HIGH 8.8
CVE-2019-3604

Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an …

Mitigation only
Fix from $1,950 2019-02-01
Total Protection HIGH 7.1
CVE-2019-3593

Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to by…

Fix: 16.0.r18+
Fix from $1,950 2019-01-28
Total Protection MEDIUM 6.5
CVE-2019-3587

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute …

Fix: 16.0.18+
Fix from $1,600 2019-01-23
Mvision Endpoint MEDIUM 6.0
CVE-2019-3584

Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated…

Fix: 18.11.31.62+
Fix from $1,600 2019-01-23
Mcafee Web Gateway HIGH 7.5
CVE-2019-3581

Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a c…

Fix: 7.8.2.5 / 8.0.2.0+
Fix from $1,950 2019-01-09
Application Change Control HIGH 7.8
CVE-2018-6668

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DL…

Fix: after 7.0.1
Fix from $1,950 2018-12-31
Application Change Control HIGH 8.0
CVE-2018-6669

A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted…

Fix: after 7.0.1
Fix from $1,950 2018-12-20
Agent HIGH 7.0
CVE-2018-6707

Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows…

Fix: after 5.0.6
Fix from $1,950 2018-12-14
Agent HIGH 7.5
CVE-2018-6706

Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custo…

Fix: after 5.0.6
Fix from $1,950 2018-12-12
Agent HIGH 7.8
CVE-2018-6705

Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary comma…

Fix: after 5.0.6
Fix from $1,950 2018-12-12
Agent HIGH 7.8
CVE-2018-6704

Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary comma…

Fix: after 5.0.6
Fix from $1,950 2018-12-12
Agent CRITICAL 9.8
CVE-2018-6703

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attacker…

Fix: 5.6.0+
Fix from $2,300 2018-12-11
True Key HIGH 7.8
CVE-2018-6755

Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbit…

Fix: after 5.1.230.7
Fix from $1,950 2018-12-06
True Key HIGH 7.8
CVE-2018-6756

Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthoriz…

Fix: after 5.1.230.7
Fix from $1,950 2018-12-06
True Key HIGH 7.8
CVE-2018-6757

Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary …

Fix: after 5.1.230.7
Fix from $1,950 2018-12-06
Threat Intelligence Exchange Server MEDIUM 5.9
CVE-2018-6695

SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man…

Fix: after 2.1.1
Fix from $1,600 2018-10-03
Data Loss Prevention Endpoint HIGH 7.8
CVE-2018-6689

Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 all…

Fix: 10.0.510 / 11.0.600+
Fix from $1,950 2018-10-03
True Key HIGH 7.8
CVE-2018-6700

DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local users to execute arbitrary c…

Fix: 5.1.165+
Fix from $1,950 2018-09-24
True Key MEDIUM 6.1
CVE-2018-6682

Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.

Fix: after 4.0.0.0
Fix from $1,600 2018-09-24
Application And Change Control HIGH 7.8
CVE-2017-3912

Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbit…

Mitigation only
Fix from $1,950 2018-09-18
Application Change Control HIGH 7.1
CVE-2018-6690

Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 H…

Fix: after 7.0.2
Fix from $1,950 2018-09-18
Endpoint Security For Linux Threat Prevention MEDIUM 5.3
CVE-2018-6693

An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting…

Fix: after 10.2.3
Fix from $1,600 2018-09-18
Drive Encryption MEDIUM 6.6
CVE-2018-6686

Authentication Bypass vulnerability in TPM autoboot in McAfee Drive Encryption (MDE) 7.1.0 and above allows physically proximate attackers to bypass …

Mitigation only
Fix from $1,600 2018-07-27
Data Loss Prevention Endpoint HIGH 7.4
CVE-2018-6683

Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.…

Fix: 10.0.505 / 11.0.405+
Fix from $1,950 2018-07-23
Mcafee Web Gateway CRITICAL 9.1
CVE-2018-6677

Directory Traversal vulnerability in the administrative user interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated administrator use…

Mitigation only
Fix from $2,300 2018-07-23