Vulnerabilities > Mcafee > High

DATE CVE VULNERABILITY TITLE RISK
2019-01-28 CVE-2019-3593 Unspecified vulnerability in Mcafee Total Protection
Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.R18 allows local users to bypass product self-protection, tamper with policies and product files, and uninstall McAfee software without permission via specially crafted malware.
local
low complexity
mcafee
7.1
2019-01-09 CVE-2019-3581 Improper Input Validation vulnerability in Mcafee web Gateway
Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a crafted HTTP request parameter.
network
low complexity
mcafee CWE-20
7.5
2018-12-31 CVE-2018-6668 Unspecified vulnerability in Mcafee Application Change Control 6.2.0/7.0.0/7.0.1
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows execution bypass, for example, with simple DLL through interpreters such as PowerShell.
local
low complexity
mcafee
7.8
2018-12-20 CVE-2018-6669 Forced Browsing vulnerability in Mcafee Application Change Control 6.2.0/7.0.0/7.0.1
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.
low complexity
mcafee CWE-425
8.0
2018-12-14 CVE-2018-6707 Resource Exhaustion vulnerability in Mcafee Agent
Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust mechanism.
local
high complexity
mcafee CWE-400
7.0
2018-12-12 CVE-2018-6706 Unspecified vulnerability in Mcafee Agent
Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.
network
low complexity
mcafee
7.5
2018-12-12 CVE-2018-6705 Unspecified vulnerability in Mcafee Agent
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
local
low complexity
mcafee
7.8
2018-12-12 CVE-2018-6704 Unspecified vulnerability in Mcafee Agent
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
local
low complexity
mcafee
7.8
2018-12-06 CVE-2018-6757 Unspecified vulnerability in Mcafee True KEY
Privilege Escalation vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware.
local
low complexity
mcafee
7.8
2018-12-06 CVE-2018-6756 Unspecified vulnerability in Mcafee True KEY
Authentication Abuse vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute unauthorized commands via specially crafted malware.
local
low complexity
mcafee
7.8