Show filters
601 Total Results
Displaying 41-50 of 601
Sort by:
Attacker Value
Unknown
CVE-2021-4038
Disclosure Date: December 09, 2021 (last updated October 07, 2023)
Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote authenticated administrator to embed a XSS in the administrator interface via specially crafted custom rules containing HTML. NSM did not correctly sanitize custom rule content in all scenarios.
0
Attacker Value
Unknown
CVE-2021-31850
Disclosure Date: December 08, 2021 (last updated October 07, 2023)
A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.
0
Attacker Value
Unknown
CVE-2021-31852
Disclosure Date: November 23, 2021 (last updated October 07, 2023)
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the UID request parameter. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extract of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.
0
Attacker Value
Unknown
CVE-2021-31851
Disclosure Date: November 23, 2021 (last updated October 07, 2023)
A Reflected Cross-Site Scripting vulnerability in McAfee Policy Auditor prior to 6.5.2 allows a remote unauthenticated attacker to inject arbitrary web script or HTML via the profileNodeID request parameters. The malicious script is reflected unmodified into the Policy Auditor web-based interface which could lead to the extraction of end user session token or login credentials. These may be used to access additional security-critical applications or conduct arbitrary cross-domain requests.
0
Attacker Value
Unknown
CVE-2021-31853
Disclosure Date: November 10, 2021 (last updated November 08, 2023)
DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
0
Attacker Value
Unknown
CVE-2021-31849
Disclosure Date: November 01, 2021 (last updated November 08, 2023)
SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.
0
Attacker Value
Unknown
CVE-2021-31848
Disclosure Date: November 01, 2021 (last updated November 16, 2023)
Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension.
0
Attacker Value
Unknown
CVE-2021-23877
Disclosure Date: October 26, 2021 (last updated November 08, 2023)
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.
0
Attacker Value
Unknown
CVE-2021-31835
Disclosure Date: October 22, 2021 (last updated November 08, 2023)
Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via a specific parameter where the administrator's entries were not correctly sanitized.
0
Attacker Value
Unknown
CVE-2021-31834
Disclosure Date: October 22, 2021 (last updated November 16, 2023)
Stored Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 11 allows ePO administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.
0