Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2020-08-13 CVE-2020-7303 Cross-site Scripting vulnerability in Mcafee Data Loss Prevention
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label.
low complexity
mcafee CWE-79
4.1
2020-08-13 CVE-2020-7302 Unrestricted Upload of File with Dangerous Type vulnerability in Mcafee Data Loss Prevention
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
network
low complexity
mcafee CWE-434
6.4
2020-08-12 CVE-2020-7301 Cross-site Scripting vulnerability in Mcafee Data Loss Prevention
Cross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to trigger alerts via the file upload tab in the DLP case management section.
network
low complexity
mcafee CWE-79
4.6
2020-08-12 CVE-2020-7300 Incorrect Authorization vulnerability in Mcafee Data Loss Prevention
Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.
network
low complexity
mcafee CWE-863
6.3
2020-08-05 CVE-2020-7298 Unspecified vulnerability in Mcafee Total Protection
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.
local
low complexity
mcafee
8.4
2020-07-15 CVE-2020-14621 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). 5.3
2020-07-15 CVE-2020-14581 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). 3.7
2020-07-15 CVE-2020-14579 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). 3.7
2020-07-15 CVE-2020-14578 Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). 3.7
2020-07-15 CVE-2020-7292 Inappropriate Encoding for Output Context vulnerability in Mcafee web Gateway
Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to click on a malicious URL.
network
low complexity
mcafee CWE-838
4.3