CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mcafee 1Enterprise Mobility Manager Apr 29, 2026 Aug 22, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not set the secure flag for the ASP.NET session cookie in an https session, which makes it easier for remote attackers to capture this cookie by int...Show more |
1Mcafee 1Enterprise Mobility Manager Apr 29, 2026 Aug 22, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 discloses the name of the user account for an IIS worker process, which allows remote attackers to obtain potentially sensitive information...Show more |
1Mcafee 1Enterprise Mobility Manager Apr 29, 2026 Aug 22, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in About.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 might allow remote attackers to inject arbitrary web script or HTML via the (1) User...Show more |
Login.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by lev...Show more |
1Mcafee 2Enterprise Mobility Manager Enterprise Mobility Manager AgentApr 29, 2026 Aug 22, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administrator may wish to unl...Show more |
1Mcafee 2Enterprise Mobility Manager Enterprise Mobility Manager AgentApr 29, 2026 Aug 22, 2012 N/A· v4 N/A· v3 3.5 LOW· v2 McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attacke...Show more |