← Back

Mcafee

mcafee

602 CVEs • 137 products

Products (137)

Click to collapse
Toggle
Web Gateway
web_gateway
Agent
agent
Email Gateway
email_gateway
Gateway
gateway
Scan Engine
scan_engine
Virusscan
virusscan
Mcafee Agent
mcafee_agent
True Key
true_key
Virex
virex
Livesafe
livesafe
Cloud Av
cloud_av
Webadvisor
webadvisor
Cma
cma
Smartfilter
smartfilter
Superscan
superscan
Asset Manager
asset_manager
File Lock
file_lock
Getsusp
getsusp
Techcheck
techcheck
Asap Virusscan
asap_virusscan
Freescan
freescan
Mcinsctl.dll
mcinsctl.dll
Antispyware
antispyware
Quickclean
quickclean
Spamkiller
spamkiller
Network Agent
network_agent
Neotrace
neotrace
Visual Trace
visual_trace
Virusscan Plus
virusscan_plus

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
1Epolicy Orchestrator
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge...Show more
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password.Show less
1Mcafee
1Epolicy Orchestrator
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML paramet...Show more
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 allows remote authenticated users to read arbitrary files via the conditionXML parameter to the taskLogTable to orionUpdateTableFilter.do.Show less
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in the login form in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to cause a denial of service via a crafted value in the domain field.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
3.6 LOW· v2
Unspecified vulnerability in McAfee Network Data Loss Prevention before (NDLP) before 9.3 allows local users to obtain sensitive information and impact integrity via unknown vectors, related to partition mounting.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The TLS/SSL Server in McAfee Network Data Loss Prevention (NDLP) before 9.3 uses weak cipher algorithms, which makes it easier for remote authenticated users to execute arbitrary code via unspecified vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect integrity, or cause a denial of service via unknown vectors, related to s...Show more
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect integrity, or cause a denial of service via unknown vectors, related to simultaneous logins.Show less
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
3.6 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password."
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
2.1 LOW· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive informati...Show more
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.Show less
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remote attackers to obtain sensitive information via unspecified vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Mcafee
1Network Data Loss Prevention
May 6, 2026
Oct 29, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network ports.