Vulnerabilities > Mcafee > High

DATE CVE VULNERABILITY TITLE RISK
2021-01-26 CVE-2021-3156 Off-by-one Error vulnerability in multiple products
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
7.8
2021-01-20 CVE-2021-1257 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent.
network
low complexity
cisco mcafee CWE-352
8.8
2020-12-01 CVE-2020-7335 Improper Privilege Management vulnerability in Mcafee Total Protection
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by creating a junction link.
local
high complexity
mcafee CWE-269
7.8
2020-11-12 CVE-2020-7332 Cross-Site Request Forgery (CSRF) vulnerability in Mcafee Endpoint Security
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.
network
low complexity
mcafee CWE-352
8.8
2020-11-12 CVE-2020-7331 Unquoted Search Path or Element vulnerability in Mcafee Endpoint Security
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
local
low complexity
mcafee CWE-428
7.8
2020-11-11 CVE-2020-7329 Server-Side Request Forgery (SSRF) vulnerability in Mcafee Mvision Endpoint
Server-side request forgery vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers trigger server-side DNS requests to arbitrary domains via carefully constructed XML files loaded by an ePO administrator.
network
low complexity
mcafee CWE-918
7.2
2020-11-11 CVE-2020-7328 Server-Side Request Forgery (SSRF) vulnerability in Mcafee Mvision Endpoint
External entity attack vulnerability in the ePO extension in McAfee MVISION Endpoint prior to 20.11 allows remote attackers to gain control of a resource or trigger arbitrary code execution via improper input validation of an HTTP request, where the content for the attack has been loaded into ePO by an ePO administrator.
network
low complexity
mcafee CWE-918
7.2
2020-10-15 CVE-2020-7334 Improper Privilege Management vulnerability in Mcafee Application and Change Control
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer.
local
low complexity
mcafee CWE-269
8.2
2020-10-14 CVE-2020-7330 Improper Privilege Management vulnerability in Mcafee Total Protection 4.0.161.1
Privilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call malicious software to execute with elevated privileges via editing of environment variables
local
low complexity
mcafee CWE-269
8.8
2020-10-07 CVE-2020-7316 Unquoted Search Path or Element vulnerability in Mcafee File and Removable Media Protection
Unquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder.
local
low complexity
mcafee CWE-428
7.8