Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2021-05-12 CVE-2021-23892 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mcafee Endpoint Security for Linux Threat Prevention
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.
local
high complexity
mcafee CWE-367
7.0
2021-04-22 CVE-2021-2161 Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
network
high complexity
oracle debian fedoraproject netapp mcafee
5.9
2021-04-15 CVE-2021-23887 Unspecified vulnerability in Mcafee Data Loss Prevention Endpoint
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses.
local
low complexity
mcafee
7.8
2021-04-15 CVE-2021-23886 Improper Handling of Exceptional Conditions vulnerability in Mcafee Data Loss Prevention Endpoint
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it.
local
low complexity
mcafee CWE-755
5.5
2021-04-15 CVE-2021-23884 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Content Security Reporter
Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.
low complexity
mcafee CWE-319
4.3
2021-04-15 CVE-2020-7308 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Endpoint Security
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS.
network
low complexity
mcafee CWE-319
6.5
2021-04-15 CVE-2020-7270 Unspecified vulnerability in Mcafee Advanced Threat Defense
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter.
network
low complexity
mcafee
4.3
2021-04-15 CVE-2020-7269 Unspecified vulnerability in Mcafee Advanced Threat Defense
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter.
network
low complexity
mcafee
4.3
2021-03-26 CVE-2021-23890 Information Exposure vulnerability in Mcafee Epolicy Orchestrator
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server.
network
low complexity
mcafee CWE-200
6.5
2021-03-26 CVE-2021-23889 Cross-site Scripting vulnerability in Mcafee Epolicy Orchestrator
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
network
low complexity
mcafee CWE-79
4.8