Vulnerabilities > Mcafee

DATE CVE VULNERABILITY TITLE RISK
2021-04-15 CVE-2021-23887 Unspecified vulnerability in Mcafee Data Loss Prevention Endpoint
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses.
local
low complexity
mcafee
7.8
2021-04-15 CVE-2021-23886 Improper Handling of Exceptional Conditions vulnerability in Mcafee Data Loss Prevention Endpoint
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it.
local
low complexity
mcafee CWE-755
5.5
2021-04-15 CVE-2021-23884 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Content Security Reporter
Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the unencrypted password of the McAfee Web Gateway (MWG) or the password of the McAfee Web Gateway Cloud Server (MWGCS) read only user used to retrieve log files for analysis in CSR.
low complexity
mcafee CWE-319
4.3
2021-04-15 CVE-2020-7308 Cleartext Transmission of Sensitive Information vulnerability in Mcafee Endpoint Security
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS.
network
low complexity
mcafee CWE-319
6.5
2021-04-15 CVE-2020-7270 Unspecified vulnerability in Mcafee Advanced Threat Defense
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter.
network
low complexity
mcafee
4.3
2021-04-15 CVE-2020-7269 Unspecified vulnerability in Mcafee Advanced Threat Defense
Exposure of Sensitive Information in the web interface in McAfee Advanced Threat Defense (ATD) prior to 4.12.2 allows remote authenticated users to view sensitive unencrypted information via a carefully crafted HTTP request parameter.
network
low complexity
mcafee
4.3
2021-03-26 CVE-2021-23890 Information Exposure vulnerability in Mcafee Epolicy Orchestrator
Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows an unauthenticated user to download McAfee product packages (specifically McAfee Agent) available in ePO repository and install them on their own machines to have it managed and then in turn get policy details from the ePO server.
network
low complexity
mcafee CWE-200
6.5
2021-03-26 CVE-2021-23889 Cross-site Scripting vulnerability in Mcafee Epolicy Orchestrator
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
network
low complexity
mcafee CWE-79
4.8
2021-03-26 CVE-2021-23888 Open Redirect vulnerability in Mcafee Epolicy Orchestrator
Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.
network
low complexity
mcafee CWE-601
6.3
2021-03-25 CVE-2021-3450 Improper Certificate Validation vulnerability in multiple products
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
7.4