Vulnerabilities > Mcafee > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-22 CVE-2021-31847 Uncontrolled Search Path Element vulnerability in Mcafee Agent
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs.
local
low complexity
mcafee CWE-427
7.8
2021-09-17 CVE-2021-31843 Link Following vulnerability in Mcafee Endpoint Security
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.
local
low complexity
mcafee CWE-59
7.8
2021-09-17 CVE-2021-31844 Classic Buffer Overflow vulnerability in Mcafee Data Loss Prevention Endpoint
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file.
local
low complexity
mcafee CWE-120
7.3
2021-09-17 CVE-2021-31845 Classic Buffer Overflow vulnerability in Mcafee Data Loss Prevention Discover
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges.
local
low complexity
mcafee CWE-120
7.3
2021-08-24 CVE-2021-3712 Out-of-bounds Read vulnerability in multiple products
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length.
7.4
2021-07-12 CVE-2021-30639 Improper Handling of Exceptional Conditions vulnerability in multiple products
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service.
network
low complexity
apache mcafee oracle CWE-755
7.5
2021-06-10 CVE-2021-31840 Uncontrolled Search Path Element vulnerability in Mcafee Agent 5.0.0/5.6.6
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs.
local
low complexity
mcafee CWE-427
7.3
2021-06-09 CVE-2021-31837 Out-of-bounds Write vulnerability in Mcafee Getsusp 3.0.0.461
Memory corruption vulnerability in the driver file component in McAfee GetSusp prior to 4.0.0 could allow a program being investigated on the local machine to trigger a buffer overflow in GetSusp, leading to the execution of arbitrary code, potentially triggering a BSOD.
local
low complexity
mcafee CWE-787
7.8
2021-06-02 CVE-2021-23894 Deserialization of Untrusted Data vulnerability in Mcafee Database Security 4.6.6/4.8.0
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
low complexity
mcafee CWE-502
8.8
2021-06-02 CVE-2021-23895 Deserialization of Untrusted Data vulnerability in Mcafee Database Security 4.6.6/4.8.0
Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server.
low complexity
mcafee CWE-502
8.0