Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2005-3657

Disclosure Date: December 21, 2005 (last updated February 22, 2025)
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.
0
Attacker Value
Unknown

CVE-2004-0831

Disclosure Date: September 14, 2004 (last updated February 22, 2025)
McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.
0
Attacker Value
Unknown

CVE-2002-2282

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.
0