Show filters
148 Total Results
Displaying 61-70 of 148
Sort by:
Attacker Value
Unknown

Juniper ATP: Persistent Cross-Site Scripting (XSS) vulnerability in file upload…

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scripts and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
0
Attacker Value
Unknown

Juniper ATP: Persistent Cross-Site Scripting vulnerability in Zone configuration

Disclosure Date: January 15, 2019 (last updated November 27, 2024)
A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. This issue affects Juniper ATP 5.0 versions prior to 5.0.3.
0
Attacker Value
Unknown

Data Loss Prevention Endpoint (DLPe) - Authentication Bypass vulnerability

Disclosure Date: October 03, 2018 (last updated November 08, 2023)
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
Attacker Value
Unknown

Endpoint Security for Linux Threat Prevention (ENSLTP) privilege escalation vu…

Disclosure Date: September 18, 2018 (last updated November 08, 2023)
An unprivileged user can delete arbitrary files on a Linux system running ENSLTP 10.5.1, 10.5.0, and 10.2.3 Hotfix 1246778 and earlier. By exploiting a time of check to time of use (TOCTOU) race condition during a specific scanning sequence, the unprivileged user is able to perform a privilege escalation to delete arbitrary files.
Attacker Value
Unknown

- Data Loss Prevention (DLP) for Windows - Exploiting Incorrectly Configured A…

Disclosure Date: July 23, 2018 (last updated November 08, 2023)
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.
Attacker Value
Unknown

McAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP…

Disclosure Date: June 13, 2018 (last updated November 08, 2023)
Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfee Network Data Loss Prevention (NDLP) before 9.3.4.1.5 allows remote attackers to disclose sensitive information or manipulate the database via a crafted authentication cookie.
0
Attacker Value
Unknown

SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint …

Disclosure Date: May 25, 2018 (last updated November 08, 2023)
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.
0
Attacker Value
Unknown

SB10193 - consumer and corporate products - Maliciously misconfigured registry …

Disclosure Date: April 03, 2018 (last updated November 08, 2023)
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
0
Attacker Value
Unknown

CVE-2017-3935

Disclosure Date: October 31, 2017 (last updated November 26, 2024)
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the intended content type.
0
Attacker Value
Unknown

CVE-2017-3934

Disclosure Date: October 31, 2017 (last updated November 26, 2024)
Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-in-the-middle attackers to expose confidential data via read files on the webserver.
0