← Back

Mcafee

mcafee

602 CVEs • 137 products

Products (137)

Click to collapse
Toggle
Web Gateway
web_gateway
Agent
agent
Email Gateway
email_gateway
Gateway
gateway
Scan Engine
scan_engine
Virusscan
virusscan
Mcafee Agent
mcafee_agent
True Key
true_key
Virex
virex
Livesafe
livesafe
Cloud Av
cloud_av
Webadvisor
webadvisor
Cma
cma
Smartfilter
smartfilter
Superscan
superscan
Asset Manager
asset_manager
File Lock
file_lock
Getsusp
getsusp
Techcheck
techcheck
Asap Virusscan
asap_virusscan
Freescan
freescan
Mcinsctl.dll
mcinsctl.dll
Antispyware
antispyware
Quickclean
quickclean
Spamkiller
spamkiller
Network Agent
network_agent
Neotrace
neotrace
Visual Trace
visual_trace
Virusscan Plus
virusscan_plus

CVEs (602)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mcafee
2Epolicy Orchestrator
Protectionpilot
Apr 23, 2026
Oct 5, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
1Mcafee
2Scan Engine
Virusscan Enterprise
Apr 16, 2026
Sep 19, 2006
N/A· v4
N/A· v3
3.7 LOW· v2
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the progra...Show more
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button, possibly due to an interface-related race condition.Show less
1Mcafee
9Antispyware
Internet Security SuitePersonal Firewall Plus+6 more
Apr 16, 2026
Aug 1, 2006
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller...Show more
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.Show less
1Mcafee
1Epolicy Orchestrator Agent
Apr 16, 2026
Jul 18, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename...Show more
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename in a PropsResponse (PackageType) request.Show less
1Mcafee
1Virusscan
Apr 16, 2026
Jul 13, 2006
N/A· v4
N/A· v3
2.1 LOW· v2
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module n...Show more
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields.Show less
1Mcafee
1Webshield Smtp
Apr 16, 2026
Apr 4, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are...Show more
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.Show less
1Mcafee
1Virex
Apr 16, 2026
Mar 3, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allow...Show more
The on-access scanner for McAfee Virex 7.7 for Macintosh, in some circumstances, might not activate when malicious content is accessed from the web browser, and might not prevent the content from being saved, which allows remote attackers to bypass virus protection, as demonstrated using the EICAR test file.Show less
1Mcafee
2Common Management Agent
Virusscan Enterprise
Apr 16, 2026
Dec 23, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run...Show more
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.Show less
1Mcafee
2Mcinsctl.dll
Virusscan Security Center
Apr 16, 2026
Dec 21, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary f...Show more
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.Show less
1Mcafee
1Internet Security Suite
Apr 16, 2026
Oct 30, 2005
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scannin...Show more
Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug."Show less
1Mcafee
1Intrushield Security Management System
Apr 16, 2026
Jul 11, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack.
1Mcafee
1Intrushield Security Management System
Apr 16, 2026
Jul 11, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or...Show more
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.Show less
1Mcafee
1Intrushield Security Management System
Apr 16, 2026
Jul 11, 2005
N/A· v4
N/A· v3
1.9 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName p...Show more
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.Show less
1Mcafee
1Antivirus Engine
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.
1Mcafee
1Antivirus Engine
Apr 16, 2026
May 2, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.
1Mcafee
1Internet Security Suite
Apr 16, 2026
Apr 18, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.
11Archive Zip
BroadcomCa+8 more
23Antivirus Engine
Archive ZipBrightstor Arcserve Backup+20 more
Apr 16, 2026
Feb 9, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero...Show more
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.Show less
11Archive Zip
BroadcomCa+8 more
23Antivirus Engine
Archive ZipBrightstor Arcserve Backup+20 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
11Archive Zip
BroadcomCa+8 more
23Antivirus Engine
Archive ZipBrightstor Arcserve Backup+20 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file f...Show more
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.Show less
11Archive Zip
BroadcomCa+8 more
23Antivirus Engine
Archive ZipBrightstor Arcserve Backup+20 more
Apr 16, 2026
Jan 27, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target s...Show more
Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.Show less