Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2017-09-01 CVE-2017-3897 Code Injection vulnerability in Mcafee Livesafe and Security Scan Plus
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
network
low complexity
mcafee CWE-94
critical
9.8
2017-08-07 CVE-2015-7704 Improper Input Validation vulnerability in multiple products
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.
network
low complexity
ntp debian netapp redhat mcafee citrix CWE-20
7.5
2017-07-12 CVE-2017-4057 Unspecified vulnerability in Mcafee Advanced Threat Defense
Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to gain elevated privileges via the GUI or GUI terminal commands.
network
low complexity
mcafee
8.8
2017-07-12 CVE-2017-4055 Missing Authentication for Critical Function vulnerability in Mcafee Advanced Threat Defense
Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to bypass ATD detection via loose enforcement of authentication and authorization.
network
low complexity
mcafee CWE-306
7.5
2017-07-12 CVE-2017-4054 Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-77
8.8
2017-07-12 CVE-2017-4053 OS Command Injection vulnerability in Mcafee Advanced Threat Defense
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-78
critical
9.8
2017-07-12 CVE-2017-4052 Missing Authentication for Critical Function vulnerability in Mcafee Advanced Threat Defense
Authentication Bypass vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to change or update any configuration settings, or gain administrator functionality via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-306
critical
9.8
2017-06-23 CVE-2017-3948 Cross-site Scripting vulnerability in Mcafee Data Loss Prevention Endpoint
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
network
low complexity
mcafee CWE-79
5.4
2017-06-19 CVE-2017-1000366 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution.
7.8
2017-05-29 CVE-2017-9287 Double Free vulnerability in multiple products
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability.
network
low complexity
openldap debian redhat mcafee oracle CWE-415
6.5