Vulnerabilities
Vulnerable Software
Mcafee:  Security Vulnerabilities
A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.
CVSS Score
7.2
EPSS Score
0.034
Published
2017-05-18
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.
CVSS Score
6.1
EPSS Score
0.109
Published
2017-05-17
Privilege Escalation vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view confidential information via modification of the HTTP request.
CVSS Score
6.5
EPSS Score
0.003
Published
2017-05-17
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-05-17
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.
CVSS Score
8.0
EPSS Score
0.004
Published
2017-05-17
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.
CVSS Score
4.5
EPSS Score
0.002
Published
2017-05-17
Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find another hole via HTTP response header.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-05-17
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-05-17
A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows remote attackers to create a Denial of Service on the active Internet Explorer tab via a crafted HTML link.
CVSS Score
4.3
EPSS Score
0.004
Published
2017-04-25
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security protection via a crafted input file.
CVSS Score
7.3
EPSS Score
0.001
Published
2017-03-31


Contact Us

Shodan ® - All rights reserved