Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mcafee Web Gateway CRITICAL 9.1
CVE-2018-6678

Configuration/Environment manipulation vulnerability in the administrative interface in McAfee Web Gateway (MWG) MWG 7.8.1.x allows authenticated adm…

No fix yet
Fix from $2,300 2018-07-23
Network Security Manager MEDIUM 5.4
CVE-2018-6681

Abuse of Functionality vulnerability in the web interface in McAfee Network Security Management (NSM) 9.1.7.11 and earlier allows authenticated users…

Fix: after 9.1.7.11
Fix from $1,600 2018-07-17
Mcafee Web Gateway CRITICAL 9.8
CVE-2018-6667

Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to exe…

Fix: after 7.8.1.5
Fix from $2,300 2018-06-26
Epolicy Orchestrator MEDIUM 6.5
CVE-2018-6671

Application Protection Bypass vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows remote authentica…

Fix: after 5.9.1
Fix from $1,600 2018-06-15
Epolicy Orchestrator MEDIUM 6.5
CVE-2018-6672

Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to v…

Fix: after 5.9.1
Fix from $1,600 2018-06-15
Mcafee Threat Intelligence Exchange CRITICAL 9.8
CVE-2017-3907

Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows…

Mitigation only
Fix from $2,300 2018-06-13
Epolicy Orchestrator CRITICAL 9.8
CVE-2017-3936

OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run a…

Mitigation only
Fix from $2,300 2018-06-13
Network Data Loss Prevention CRITICAL 9.1
CVE-2017-3968

Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Preventio…

Fix: 8.2.7.42.2 / 9.3.4.1.5+
Fix from $2,300 2018-06-13
Network Security Manager CRITICAL 9.8
CVE-2017-3962

Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before…

Fix: 8.2.7.42.2+
Fix from $2,300 2018-06-12
Network Security Manager HIGH 8.8
CVE-2017-3960

Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated u…

Fix: 8.2.7.42.2+
Fix from $1,950 2018-06-12
Common Catalog MEDIUM 6.5
CVE-2018-6670

External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential info…

Fix: 2.0.3+
Fix from $1,600 2018-06-07
Management Of Native Encryption HIGH 7.8
CVE-2018-6662

Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to gain elevated privileges via a …

Fix: 4.1.4+
Fix from $1,950 2018-06-05
Data Loss Prevention Endpoint HIGH 8.8
CVE-2018-6664

Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint befo…

Fix: 10.0.500 / 11.0.400+
Fix from $1,950 2018-05-25
Network Security Manager MEDIUM 5.4
CVE-2017-3961

Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows authenticated user…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-05-25
Tunnelbear CRITICAL 9.8
CVE-2018-10381

TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service est…

Mitigation only
Fix from $2,300 2018-04-26
Network Security Manager HIGH 8.8
CVE-2017-3965

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42…

Fix: 8.2.7.42.2+
Fix from $1,950 2018-04-04
Network Security Manager MEDIUM 6.5
CVE-2017-3971

Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential …

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Network Security Manager MEDIUM 6.3
CVE-2017-3966

Exploitation of session variables, resource IDs and other trusted credentials vulnerability in the web interface in McAfee Network Security Managemen…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Network Security Manager MEDIUM 6.1
CVE-2017-3967

Target influence via framing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows remote attackers…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Network Security Manager MEDIUM 5.9
CVE-2017-3969

Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle at…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Network Security Manager MEDIUM 5.4
CVE-2017-3964

Reflective Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attacke…

Fix: 8.2.7.42.2+
Fix from $1,600 2018-04-04
Network Security Manager CRITICAL 9.8
CVE-2017-3972

Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers …

Fix: 8.2.7.42.2+
Fix from $2,300 2018-04-03
Epolicy Orchestrator MEDIUM 5.4
CVE-2018-6659

Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to …

Mitigation only
Fix from $1,600 2018-04-02
True Key HIGH 7.8
CVE-2018-6661

DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not …

Fix: after 4.20
Fix from $1,950 2018-04-02
Network Data Loss Prevention HIGH 7.5
CVE-2017-3935

Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the res…

Fix: after 9.3.0
Fix from $1,950 2017-10-31
Network Data Loss Prevention MEDIUM 5.9
CVE-2017-3934

Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-i…

Fix: after 9.3.0
Fix from $1,600 2017-10-31
Network Data Loss Prevention MEDIUM 5.4
CVE-2017-3933

Embedding Script (XSS) in HTTP Headers vulnerability in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view co…

Patch available
Fix from $1,600 2017-10-31
Livesafe CRITICAL 9.8
CVE-2017-3897EPSS 12%

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security…

Fix: after 16.0.2
Fix from $2,300 2017-09-01
Livesafe MEDIUM 5.9
CVE-2017-3898

A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo…

Fix: after 16.0.2
Fix from $1,600 2017-09-01
Advanced Threat Defense CRITICAL 9.8
CVE-2017-4052

Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated us…

Patch available
Fix from $2,300 2017-07-12