McAfee records
607 published records for vendor mcafee.
Researcher profile
- Entered KEV
- 2 · 0.3%
- Weaponized
- 8 · 1.3%
- Pre-auth RCE
- 45
- With a fix record
- 12.5%
- Median publish → KEV
- 351 days
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls56
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')52
- CWE-269 Improper Privilege Management31
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-287 Improper Authentication20
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer17
The weakness classes this vendor ships most often: where to look.
CWEAll records
607 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
91Now | CVE-2021-3156Weaponized | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root sudo project · sudo · CWE-193 | High7.8 | KEV | 100.0% | Jan 26, 2021 |
62This week | CVE-2006-5156Weaponized | Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbimcafee · epolicy orchestrator | Critical10.0 | — | 74.0% | Oct 5, 2006 |
61This week | CVE-2021-23874Weaponized | McAfee Total Protection (MTP) privilege escalation vulnerabilitymcafee · total protection · CWE-269 | High7.8 | KEV | 1.0% | Feb 10, 2021 |
56Plan | CVE-2019-9515No exploit | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 87.4% | Aug 13, 2019 |
56Plan | CVE-2020-13935Proof of concept | The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.apache · tomcat · CWE-835 | High7.5 | — | 86.6% | Jul 14, 2020 |
55Plan | CVE-2019-9514No exploit | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 82.8% | Aug 13, 2019 |
54Plan | CVE-2019-9513No exploit | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 81.6% | Aug 13, 2019 |
49Plan | CVE-2004-0932Proof of concept | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | High7.5 | — | 63.6% | Jan 27, 2005 |
48Plan | CVE-2019-9511Proof of concept | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of serviceapple · swiftnio · CWE-400 | High7.5 | — | 59.5% | Aug 13, 2019 |
47Plan | CVE-2012-1456No exploit | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Medium4.3 | — | 99.9% | Mar 21, 2012 |
47Plan | CVE-2012-1459No exploit | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 99.8% | Mar 21, 2012 |
47Plan | CVE-2012-1446No exploit | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Medium4.3 | — | 99.7% | Mar 21, 2012 |
47Plan | CVE-2012-1443No exploit | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Medium4.3 | — | 99.6% | Mar 21, 2012 |
47Plan | CVE-2012-1442No exploit | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwascat · quick heal · CWE-264 | Medium4.3 | — | 98.9% | Mar 21, 2012 |
47Plan | CVE-2006-6707Weaponized | Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTrmcafee · neotrace | High7.5 | — | 56.2% | Dec 22, 2006 |
46Plan | CVE-2012-1457No exploit | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.anti-virus · vba32 · CWE-264 | Medium4.3 | — | 98.3% | Mar 21, 2012 |
46Plan | CVE-2012-1453No exploit | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Treca · etrust vet antivirus · CWE-264 | Medium4.3 | — | 97.7% | Mar 21, 2012 |
46Plan | CVE-2012-1431No exploit | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2012-1430No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2012-4598Weaponized | An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary codemcafee · mcafee virtual technician | Critical9.3 | — | 29.4% | Aug 22, 2012 |
45Plan | CVE-2012-1463No exploit | The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 94.2% | Mar 21, 2012 |
45Plan | CVE-2012-1425No exploit | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1antiy · avl sdk · CWE-264 | Medium4.3 | — | 93.2% | Mar 21, 2012 |
45Plan | CVE-2012-1429No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.comodo · comodo antivirus · CWE-264 | Medium4.3 | — | 92.5% | Mar 21, 2012 |
45Plan | CVE-2012-1461No exploit | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Medium4.3 | — | 91.7% | Mar 21, 2012 |
45Plan | CVE-2020-9484Proof of concept | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is ableapache · tomcat · CWE-502 | High7.0 | — | 55.5% | May 20, 2020 |
- CVE-2021-315691Now
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root
HighCVSS 7.8KEVWeaponizedEPSS 100%sudo project · sudoJan 26, 2021
- CVE-2006-515662This week
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbi
CriticalCVSS 10.0WeaponizedEPSS 74%mcafee · epolicy orchestratorOct 5, 2006
- CVE-2021-2387461This week
McAfee Total Protection (MTP) privilege escalation vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 1%mcafee · total protectionFeb 10, 2021
- CVE-2019-951556Plan
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 87%apple · swiftnioAug 13, 2019
- CVE-2020-1393556Plan
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.
HighCVSS 7.5Proof of conceptEPSS 87%apache · tomcatJul 14, 2020
- CVE-2019-951455Plan
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 83%apple · swiftnioAug 13, 2019
- CVE-2019-951354Plan
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
HighCVSS 7.5No exploitEPSS 82%apple · swiftnioAug 13, 2019
- CVE-2004-093249Plan
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
HighCVSS 7.5Proof of conceptEPSS 64%ca · etrust antivirusJan 27, 2005
- CVE-2019-951148Plan
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
HighCVSS 7.5Proof of conceptEPSS 60%apple · swiftnioAug 13, 2019
- CVE-2012-145647Plan
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
MediumCVSS 4.3No exploitEPSS 100%avg · avg anti-virusMar 21, 2012
- CVE-2012-145947Plan
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
MediumCVSS 4.3No exploitEPSS 100%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-144647Plan
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
MediumCVSS 4.3No exploitEPSS 100%ca · etrust vet antivirusMar 21, 2012
- CVE-2012-144347Plan
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
MediumCVSS 4.3No exploitEPSS 100%cat · quick healMar 21, 2012
- CVE-2012-144247Plan
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwas
MediumCVSS 4.3No exploitEPSS 99%cat · quick healMar 21, 2012
- CVE-2006-670747Plan
Stack-based buffer overflow in the NeoTraceExplorer.NeoTraceLoader ActiveX control (NeoTraceExplorer.dll) in NeoTrace Express 3.25 and NeoTr
HighCVSS 7.5WeaponizedEPSS 56%mcafee · neotraceDec 22, 2006
- CVE-2012-145746Plan
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.
MediumCVSS 4.3No exploitEPSS 98%anti-virus · vba32Mar 21, 2012
- CVE-2012-145346Plan
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Tre
MediumCVSS 4.3No exploitEPSS 98%ca · etrust vet antivirusMar 21, 2012
- CVE-2012-143146Plan
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-143046Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-459846Plan
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code
CriticalCVSS 9.3WeaponizedEPSS 29%mcafee · mcafee virtual technicianAug 22, 2012
- CVE-2012-146345Plan
The ELF file parser in AhnLab V3 Internet Security 2011.01.18.00, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, Command Antivirus 5
MediumCVSS 4.3No exploitEPSS 94%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-142545Plan
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1
MediumCVSS 4.3No exploitEPSS 93%antiy · avl sdkMar 21, 2012
- CVE-2012-142945Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.
MediumCVSS 4.3No exploitEPSS 92%comodo · comodo antivirusMar 21, 2012
- CVE-2012-146145Plan
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
MediumCVSS 4.3No exploitEPSS 92%anti-virus · vba32Mar 21, 2012
- CVE-2020-948445Plan
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able
HighCVSS 7.0Proof of conceptEPSS 56%apache · tomcatMay 20, 2020