Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2012-4591
About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, wh…
Enterprise Mobility Manager
after 9.6
MEDIUM 5.0
CVE-2012-4592
The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, w…
Enterprise Mobility Manager
after 9.6
MEDIUM 5.0
CVE-2012-4593
McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attribu…
Application Control
Mitigation only
HIGH 7.5
CVE-2011-5100
The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obt…
Firewall Reporter
after 5.1.0.6
MEDIUM 6.8
CVE-2012-4581
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl…
Email And Web Security
Mitigation only
MEDIUM 5.0
CVE-2011-5101
The Rumor technology in McAfee SaaS Endpoint Protection before 5.2.4 allows remote attackers to relay e-mail messages via unspecified vectors, as dem…
Saas Endpoint Protection
after 5.2.3
HIGH 9.3
CVE-2009-5118
Untrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an uns…
Virusscan Enterprise
after 8.5i
MEDIUM 6.5
CVE-2009-5115
McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenti…
Common Management Agent
Mitigation only
MEDIUM 6.5
CVE-2009-5116
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin acces…
Linuxshield
after 1.5.1
MEDIUM 6.4
CVE-2010-3496
McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, whi…
Virusscan Enterprise
No fix yet
MEDIUM 5.0
CVE-2012-2212
McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname i…
Web Gateway
Mitigation only
MEDIUM 6.8
CVE-2011-3006
The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyAS…
Saas Endpoint Protection
after 5.2.1
MEDIUM 6.8
CVE-2011-3007
The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files …
Saas Endpoint Protection
after 5.2.1
MEDIUM 6.5
CVE-2010-2116
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privi…
Email Gateway
No fix yet
HIGH 7.8
CVE-2009-3339
Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors,…
Email And Web Security Appliance
No fix yet
HIGH 9.3
CVE-2009-1491
McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, …
Groupshield
No fix yet
HIGH 7.6
CVE-2009-1348
The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microso…
Active Virus Defense
Patch available
MEDIUM 6.8
CVE-2008-3605
Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to con…
Encrypted Usb Manager
Patch available
MEDIUM 5.0
CVE-2008-1855EPSS 8%
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot…
Cma
after 3.6.0.574
MEDIUM 5.4
CVE-2008-1357EPSS 6%
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used …
Agent
No fix yet
HIGH 8.8
CVE-2008-0127EPSS 9%
The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute a…
E Business Server
after 8.5.2
HIGH 9.3
CVE-2007-2957EPSS 6%
Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute…
E Business Server
after 8.5.2
HIGH 7.6
CVE-2006-5271
Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and ea…
E Business Server
Mitigation only
HIGH 7.6
CVE-2006-5273EPSS 6%
Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.4…
Common Management Agent
after 3.6.0.453
HIGH 7.6
CVE-2006-5274
Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows …
Common Management Agent
Patch available
HIGH 7.5
CVE-2006-5272
Stack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.…
Common Management Agent
after 3.6.0.453
HIGH 10.0
CVE-2007-2584EPSS 10%
Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCent…
Security Center
Patch available
HIGH 7.9
CVE-2007-2152
Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitra…
Virusscan Enterprise
after 8.0i
MEDIUM 5.0
CVE-2007-2151
The administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (servi…
E Business Server
Patch available
HIGH 7.5
CVE-2007-1538
McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password pr…
Virusscan Enterprise
Mitigation only