Show filters
242 Total Results
Displaying 111-120 of 242
Sort by:
Attacker Value
Unknown
CVE-2021-33572
Disclosure Date: June 03, 2021 (last updated February 22, 2025)
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.
0
Attacker Value
Unknown
CVE-2021-3485
Disclosure Date: May 21, 2021 (last updated February 22, 2025)
An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.
0
Attacker Value
Unknown
CVE-2020-15279
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.
0
Attacker Value
Unknown
CVE-2021-23892
Disclosure Date: May 12, 2021 (last updated February 22, 2025)
By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.
0
Attacker Value
Unknown
CVE-2020-7308
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI) servers using DNS allows a remote attacker to view the requests from ENS and responses from GTI over DNS. By gaining control of an intermediate DNS server or altering the network DNS configuration, it is possible for an attacker to intercept requests and send their own responses.
0
Attacker Value
Unknown
CVE-2020-26200
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
A component of Kaspersky custom boot loader allowed loading of untrusted UEFI modules due to insufficient check of their authenticity. This component is incorporated in Kaspersky Rescue Disk (KRD) and was trusted by the Authentication Agent of Full Disk Encryption in Kaspersky Endpoint Security (KES). This issue allowed to bypass the UEFI Secure Boot security feature. An attacker would need physical access to the computer to exploit it. Otherwise, local administrator privileges would be required to modify the boot loader component.
0
Attacker Value
Unknown
CVE-2021-24092
Disclosure Date: February 25, 2021 (last updated February 22, 2025)
Microsoft Defender Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2021-23882
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the Access Control rules will prevent modification prior to up an upgrade.
0
Attacker Value
Unknown
CVE-2021-23878
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine
0
Attacker Value
Unknown
CVE-2021-23883
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.
0