Vulnerabilidades em McAfee

106 resultados
Análise Vexday

Com 104 CVEs catalogadas e nenhuma atividade registrada no CISA KEV, o perfil de risco ativo do McAfee situa-se abaixo da média geral do catálogo, o que indica pressão de exploração em produção relativamente contida no momento. Das vulnerabilidades existentes, 3 são de severidade crítica e 5 contam com prova de conceito pública disponível, o que ainda representa superfície de risco para ambientes sem patches atualizados. O maior EPSS observado é de 0,1168, associado a CVE-2017-3897, uma vulnerabilidade de idade considerável cuja probabilidade de exploração persiste e merece atenção em inventários legados. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), padrão que sugere oportunidades de melhoria nos controles de sanitização de entrada ao longo da base de código histórica do vendor.

CVE-2017-4057Privilege Escalation vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticaEPSS 1.2%CVE-2017-4055Exploitation of Authentication vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote EPSS 1.2%CVE-2018-6678LOWMcAfee Web Gateway (MWG) - Configuration/Environment manipulation vulnerabilityEPSS 1.2%CVE-2018-6672MEDIUMSB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablityEPSS 1.2%CVE-2019-3660HIGHAdvanced Threat Defense (ATD) - Improper Neutralization of HTTP requestsEPSS 1.2%CVE-2017-4015Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbEPSS 1.2%CVE-2016-8030A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows remote attackers toEPSS 1.2%CVE-2018-6757HIGHTrue Key (TK) Windows Client - Privilege Escalation vulnerabilityEPSS 1.1%CVE-2019-3661HIGHAdvanced Threat Defense (ATD) - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')EPSS 1.1%CVE-2019-3651HIGHAdvanced Threat Defense (ATD) - Information Disclosure vulnerabilityEPSS 1.1%CVE-2017-4013Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information viEPSS 1.0%CVE-2017-4017User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via EPSS 1.0%CVE-2017-4016Web Server method disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to exploit and find aEPSS 1.0%CVE-2021-31849HIGHData Loss Prevention (DLP) ePO extension - SQL injectionEPSS 1.0%CVE-2018-6659LOWSB10228 ePO Reflected Cross-Site Scripting vulnerabilityEPSS 1.0%CVE-2017-3935Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing oEPSS 1.0%CVE-2018-6756HIGHTrue Key (TK) Windows Client - Authentication Abuse vulnerabilityEPSS 1.0%CVE-2020-7318MEDIUMePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerabilityEPSS 1.0%CVE-2020-7305MEDIUMDLP ePO extension - Privilege escalationEPSS 1.0%CVE-2022-0815MEDIUMMcAfee WebAdvisor - Extension Fingerprinting vulnerabilityEPSS 1.0%