Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2019-02-21 CVE-2018-6687 Infinite Loop vulnerability in Mcafee Getsusp 3.0.0.461
Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifically crafted file .
local
low complexity
mcafee CWE-835
5.5
2019-02-13 CVE-2019-3610 Information Exposure vulnerability in Mcafee True KEY 3.1.9211.0
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware.
local
low complexity
mcafee CWE-200
5.5
2019-02-01 CVE-2019-3604 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Epolicy Orchestrator
Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an authenticated user's session via unspecified vectors.
network
low complexity
mcafee CWE-352
8.8
2019-01-28 CVE-2019-3593 Unspecified vulnerability in Mcafee Total Protection
Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without permission via specially crafted malware.
local
low complexity
mcafee
7.1
2019-01-23 CVE-2019-3587 Untrusted Search Path vulnerability in Mcafee Total Protection 4.0.161.1/4.0.176.1/4.6
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.
local
low complexity
mcafee CWE-426
6.5
2019-01-23 CVE-2019-3584 Improper Authentication vulnerability in Mcafee Mvision Endpoint
Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.11.31.62) allows authenticated administrator users --> administrators to Remove MVision Endpoint via unspecified vectors.
local
low complexity
mcafee CWE-287
6.0
2019-01-09 CVE-2019-3581 Improper Input Validation vulnerability in Mcafee web Gateway
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-20
7.5
2018-12-31 CVE-2018-6668 Unspecified vulnerability in Mcafee Application Change Control 6.2.0/7.0.0/7.0.1
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DLL through interpreters such as PowerShell.
local
low complexity
mcafee
7.8
2018-12-20 CVE-2018-6669 Forced Browsing vulnerability in Mcafee Application Change Control 6.2.0/7.0.0/7.0.1
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.
low complexity
mcafee CWE-425
8.0
2018-12-14 CVE-2018-6707 Resource Exhaustion vulnerability in Mcafee Agent
Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.
local
high complexity
mcafee CWE-400
7.0