Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.8
CVE-2015-2759
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hot…
Data Loss Prevention Endpoint
after 9.3.400
MEDIUM 6.5
CVE-2015-2758
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain…
Data Loss Prevention Endpoint
after 9.3.400
MEDIUM 6.5
CVE-2015-1616
SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users …
Data Loss Prevention Endpoint
after 9.3.300
MEDIUM 6.9
CVE-2015-1305
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privilege…
Data Loss Prevention Endpoint
after 9.3.300
MEDIUM 5.0
CVE-2015-0922EPSS 13%
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows …
Epolicy Orchestrator
after 4.6.8
HIGH 7.5
CVE-2014-8533
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.
Network Data Loss Prevention
after 9.2.2
HIGH 7.5
CVE-2014-8522
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers t…
Network Data Loss Prevention
after 9.2.2
HIGH 7.5
CVE-2014-8530
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect in…
Network Data Loss Prevention
after 9.2.2
MEDIUM 6.8
CVE-2014-8523
Cross-site request forgery (CSRF) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to hijack the authen…
Network Data Loss Prevention
after 9.2.2
MEDIUM 6.5
CVE-2014-8531
The TLS/SSL Server in McAfee Network Data Loss Prevention (NDLP) before 9.3 uses weak cipher algorithms, which makes it easier for remote authenticat…
Network Data Loss Prevention
after 9.2.2
MEDIUM 5.0
CVE-2014-8520
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network por…
Network Data Loss Prevention
after 9.2.2
MEDIUM 5.0
CVE-2014-8524
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remot…
Network Data Loss Prevention
after 9.2.2
MEDIUM 5.0
CVE-2014-8525
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes i…
Network Data Loss Prevention
after 9.2.2
MEDIUM 6.8
CVE-2014-2390
Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x befor…
Network Security Manager
6.1.15.39 / 7.1.5.15+
MEDIUM 6.5
CVE-2014-2587
SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL co…
Asset Manager
No fix yet
MEDIUM 6.3
CVE-2014-2205
The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to…
Epolicy Orchestrator
after 4.6.7
MEDIUM 6.8
CVE-2014-1473
Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow re…
Vulnerability Manager
after 7.5.5
HIGH 9.0
CVE-2013-7103
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in …
Email Gateway
No fix yet
HIGH 9.0
CVE-2013-7104
McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) …
Email Gateway
No fix yet
MEDIUM 6.5
CVE-2013-7092
Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbi…
Email Gateway
No fix yet
HIGH 8.5
CVE-2013-6349
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vect…
Email Gateway
Mitigation only
MEDIUM 5.0
CVE-2013-3627
FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to …
Agent
4.5.0.1927 / 4.6.0.3258+
MEDIUM 6.5
CVE-2013-4882
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agen…
Epolicy Orchestrator
after 4.6.6
HIGH 7.9
CVE-2013-0140
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote att…
Epolicy Orchestrator
after 4.5.6
HIGH 8.2
CVE-2012-5879EPSS 5%
An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cr…
Mcafee Virtual Technician
after 6.5.0.2101
HIGH 7.8
CVE-2012-4014
Unspecified vulnerability in McAfee Email Anti-virus (formerly WebShield SMTP) allows remote attackers to cause a denial of service via unknown vecto…
Email And Web Security
No fix yet
MEDIUM 6.2
CVE-2010-5166
Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous c…
Total Protection 2010
Mitigation only
HIGH 10.0
CVE-2012-4599
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBo…
Smartfilter Administration
after 4.2.1
HIGH 9.3
CVE-2012-4598EPSS 29%
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause…
Mcafee Virtual Technician
after 6.3.0.1911
HIGH 7.5
CVE-2012-4595
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack…
Email And Web Security
Mitigation only