mcafee
602 tracked vulnerabilities.
CVE-2021-31845
HIGH
McAfee Data Loss Prevention Discover < 11.6.100 - Remote Code Execution via Crafted Ami Pro File
Sep 17, 2021
CVSS 8.4
EPSS 0.01
CVE-2021-31844
HIGH
McAfee Data Loss Prevention Endpoint < 11.6.200 - Local Privilege Escalation via Ami Pro File Parsing
Sep 17, 2021
CVSS 8.2
EPSS 0.00
CVE-2021-31843
HIGH
McAfee Endpoint Security < 10.7.0 - Improper Privilege Management via Junction Link Manipulation
Sep 17, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-31842
MEDIUM
McAfee Endpoint Security < 10.7.0 - Denial of Service via XML Entity Expansion in EPDeploy.xml
Sep 17, 2021
CVSS 5.0
EPSS 0.00
CVE-2021-3712
HIGH
OpenSSL 1.0.2-1.0.2y 1.1.1-1.1.1k - Out-of-bounds Read in ASN.1 String Processing
Aug 24, 2021
CVSS 7.4
EPSS 0.00
CVE-2021-2432
LOW
Oracle JDK 7u301 - Unauthenticated Partial Denial of Service via JNDI
Jul 21, 2021
CVSS 3.7
EPSS 0.00
CVE-2021-33037
MEDIUM
Apache Tomcat <10.0.7-8.5.67 - Info Disclosure
Jul 12, 2021
CVSS 5.3
EPSS 0.02
CVE-2021-30639
HIGH
Apache Tomcat 10.0.3-10.0.4, 9.0.44, 8.5.64 - Denial of Service via Non-Blocking I/O Error Flag
Jul 12, 2021
CVSS 7.5
EPSS 0.00
CVE-2021-31838
HIGH
McAfee MVISION EDR < 3.4.0 - Authenticated OS Command Injection via Execute Reaction
Jun 29, 2021
CVSS 8.4
EPSS 0.03
CVE-2021-31840
HIGH
McAfee Agent for Windows < 5.7.3 - Authenticated DLL Preloading Attack via Unsigned DLLs
Jun 10, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-31839
MEDIUM
McAfee Agent for Windows < 5.7.3 - Improper Privilege Management in Event Log
Jun 10, 2021
CVSS 4.8
EPSS 0.00
CVE-2021-31837
HIGH
McAfee GetSusp < 4.0.0 - Memory Corruption via Driver File Component
Jun 09, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-31832
MEDIUM
McAfee Data Loss Prevention < 11.6.200 - Stored Cross-Site Scripting in Alert Configuration Text Field
Jun 09, 2021
CVSS 5.2
EPSS 0.00
CVE-2021-31830
MEDIUM
McAfee Database Security < 4.8.2 - Stored Cross-Site Scripting in Database Name Configuration
Jun 03, 2021
CVSS 5.9
EPSS 0.00
CVE-2021-31831
MEDIUM
McAfee DBSec <4.8.2 - Info Disclosure
Jun 03, 2021
CVSS 4.9
EPSS 0.00
CVE-2021-23896
LOW
McAfee Database Security < 4.8.2 - Cleartext Transmission of Sensitive Information in Administrator Interface
Jun 02, 2021
CVSS 3.2
EPSS 0.00
CVE-2021-23895
CRITICAL
McAfee Database Security < 4.8.2 - Authenticated Remote Code Execution via Java Deserialization
Jun 02, 2021
CVSS 9.0
EPSS 0.01
CVE-2021-23894
CRITICAL
McAfee Database Security < 4.8.2 - Unauthenticated Remote Code Execution via Java Deserialization
Jun 02, 2021
CVSS 9.6
EPSS 0.04
CVE-2021-23892
HIGH
McAfee Endpoint Security for Linux Threat Prevention 10.5.0-10.7.5 - Privilege Escalation via TOCTOU Race Condition
May 12, 2021
CVSS 8.2
EPSS 0.00
CVE-2021-23891
HIGH
McAfee Total Protection < 16.0.32 - Privilege Escalation via Client Token Impersonation
May 12, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-23872
HIGH
McAfee Total Protection < 16.0.32 - Privilege Escalation via File Lock Symbolic Link Manipulation
May 12, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-2161
MEDIUM
Oracle JDK and JRE - Unauthenticated Data Manipulation via Multiple Protocols
Apr 22, 2021
CVSS 5.9
EPSS 0.01
CVE-2021-23887
HIGH
McAfee Data Loss Prevention Endpoint < 11.6.100.41 - Privilege Escalation via hdlphook Driver Memory Manipulation
Apr 15, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-23886
MEDIUM
McAfee Data Loss Prevention Endpoint < 11.6.100.41 - Denial of Service via Process Suspension and Memory Modification
Apr 15, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-23884
MEDIUM
McAfee Content Security Reporter < 2.8.0 - Cleartext Transmission of Sensitive Information
Apr 15, 2021
CVSS 4.3
EPSS 0.00
Products
epolicy_orchestrator 86
web_gateway 41
endpoint_security 37
network_data_loss_prevention 31
virusscan_enterprise 29
advanced_threat_defense 26
data_loss_prevention_endpoint 26
total_protection 26
agent 25
email_gateway 20
network_security_manager 19
gateway 13
data_loss_prevention 12
scan_engine 12
email_and_web_security 10
mcafee_agent 10
virusscan 10
antivirus_engine 9
enterprise_security_manager 9
policy_auditor 9
database_security 8
true_key 8
Network Data Loss Prevention (NDLP) 7
active_response 7
application_control 7
security_scan_plus 7
threat_intelligence_exchange_server 7
application_and_change_control 6
e-business_server 6
enterprise_mobility_manager 6
Quick Filters