Show filters
91 Total Results
Displaying 81-90 of 91
Sort by:
Attacker Value
Unknown
CVE-2007-1498
Disclosure Date: March 16, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.
0
Attacker Value
Unknown
CVE-2006-5156
Disclosure Date: October 05, 2006 (last updated October 04, 2023)
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
0
Attacker Value
Unknown
CVE-2006-3623
Disclosure Date: July 18, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in Framework Service component in McAfee ePolicy Orchestrator agent 3.5.0.x and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the directory and filename in a PropsResponse (PackageType) request.
0
Attacker Value
Unknown
CVE-2005-2554
Disclosure Date: August 12, 2005 (last updated February 22, 2025)
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.
0
Attacker Value
Unknown
CVE-2004-0038
Disclosure Date: June 14, 2004 (last updated February 22, 2025)
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.
0
Attacker Value
Unknown
CVE-2004-0095
Disclosure Date: February 17, 2004 (last updated February 22, 2025)
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
0
Attacker Value
Unknown
CVE-2003-0149
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Heap-based buffer overflow in ePO agent for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request containing long parameters.
0
Attacker Value
Unknown
CVE-2003-0616
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
0
Attacker Value
Unknown
CVE-2003-0610
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Directory traversal vulnerability in ePO agent for McAfee ePolicy Orchestrator 3.0 allows remote attackers to read arbitrary files via a certain HTTP request.
0
Attacker Value
Unknown
CVE-2003-0148
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
The default installation of MSDE via McAfee ePolicy Orchestrator 2.0 through 3.0 allows attackers to execute arbitrary code via a series of steps that (1) obtain the database administrator username and encrypted password in a configuration file from the ePO server using a certain request, (2) crack the password due to weak cryptography, and (3) use the password to pass commands through xp_cmdshell.
0