Vulnerability index

Browse CVEs

391 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advanced Threat Defense CRITICAL 9.8
CVE-2017-4053

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users …

Patch available
Fix from $2,300 2017-07-12
Advanced Threat Defense HIGH 8.8
CVE-2017-4054

Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to…

Patch available
Fix from $1,950 2017-07-12
Advanced Threat Defense HIGH 8.8
CVE-2017-4057

Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users…

Patch available
Fix from $1,950 2017-07-12
Advanced Threat Defense HIGH 7.5
CVE-2017-4055

Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthent…

Patch available
Fix from $1,950 2017-07-12
Data Loss Prevention Endpoint MEDIUM 5.4
CVE-2017-3948

Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users …

Patch available
Fix from $1,600 2017-06-23
Epolicy Orchestrator HIGH 7.2
CVE-2017-3980

A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authe…

Fix: after 5.9.1
Fix from $1,950 2017-05-18
Network Data Loss Prevention HIGH 8.0
CVE-2017-4014

Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, …

Fix: after 9.3.0
Fix from $1,950 2017-05-17
Network Data Loss Prevention MEDIUM 6.5
CVE-2017-4012

Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confid…

Fix: after 9.3.0
Fix from $1,600 2017-05-17
Network Data Loss Prevention MEDIUM 6.1
CVE-2017-4011

Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get…

Fix: after 9.3.0
Fix from $1,600 2017-05-17
Network Data Loss Prevention MEDIUM 5.3
CVE-2017-4013

Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP re…

Fix: after 9.3.0
Fix from $1,600 2017-05-17
Network Data Loss Prevention MEDIUM 5.3
CVE-2017-4016

Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another ho…

Fix: after 9.3.0
Fix from $1,600 2017-05-17
Network Data Loss Prevention MEDIUM 5.3
CVE-2017-4017

User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appli…

Fix: after 9.3.0
Fix from $1,600 2017-05-17
Anti Malware Scan Engine HIGH 7.3
CVE-2016-8032

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security …

Patch available
Fix from $1,950 2017-03-31
Anti Malware Scan Engine HIGH 7.3
CVE-2016-8031

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security prot…

Patch available
Fix from $1,950 2017-03-28
Epolicy Orchestrator CRITICAL 10.0
CVE-2016-8027EPSS 6%

SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attac…

Fix: after 5.3.2
Fix from $2,300 2017-03-14
Virusscan Enterprise HIGH 8.1
CVE-2016-8023EPSS 9%

Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Virusscan Enterprise HIGH 8.1
CVE-2016-8024EPSS 9%

Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allow…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Security Scan Plus HIGH 7.8
CVE-2016-8026

Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain e…

Fix: after 3.11.469
Fix from $1,950 2017-03-14
Virusscan Enterprise HIGH 7.5
CVE-2016-8022EPSS 13%

Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Advanced Threat Defense MEDIUM 6.5
CVE-2017-3899

SQL injection vulnerability in Intel Security Advanced Threat Defense (ATD) Linux 3.6.0 and earlier allows remote authenticated users to obtain produ…

Fix: after 3.8.0
Fix from $1,600 2017-03-14
Virusscan Enterprise MEDIUM 6.2
CVE-2016-8025EPSS 7%

SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain produ…

Fix: after 2.0.3
Fix from $1,600 2017-03-14
Virusscan Enterprise MEDIUM 5.0
CVE-2016-8021

Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote …

Fix: after 2.0.3
Fix from $1,600 2017-03-14
Cloud Analysis And Deconstructive Services CRITICAL 9.8
CVE-2014-9921

Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier …

Fix: after 1.0.0.4d
Fix from $2,300 2017-03-14
Epo Deep Command HIGH 8.8
CVE-2015-8988

Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 …

Patch available
Fix from $1,950 2017-03-14
Vulnerability Manager HIGH 8.8
CVE-2015-8989

Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earli…

Fix: after 7.5.8
Fix from $1,950 2017-03-14
Security Scan Plus HIGH 8.8
CVE-2016-8008

Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of …

Fix: after 3.11.376
Fix from $1,950 2017-03-14
Virusscan Enterprise HIGH 8.0
CVE-2016-8020EPSS 11%

Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…

Fix: after 2.0.3
Fix from $1,950 2017-03-14
Application Control HIGH 7.8
CVE-2016-8009

Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected …

No fix yet
Fix from $1,950 2017-03-14
Application Control HIGH 7.8
CVE-2016-8010

Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and …

Fix: after 10.2
Fix from $1,950 2017-03-14
Data Loss Prevention Endpoint HIGH 7.8
CVE-2016-8012

Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Ex…

Fix: after 9.4.200
Fix from $1,950 2017-03-14