CVE-2019-3595
- EPSS 0.19%
- Published 24.07.2019 15:15:12
- Last modified 21.11.2024 04:42:13
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privil...
CVE-2019-3591
- EPSS 0.31%
- Published 24.07.2019 15:15:12
- Last modified 21.11.2024 04:42:13
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to...
CVE-2018-6689
- EPSS 0.04%
- Published 03.10.2018 12:29:00
- Last modified 21.11.2024 04:11:06
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
CVE-2018-6683
- EPSS 0.04%
- Published 23.07.2018 15:29:00
- Last modified 21.11.2024 04:11:06
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when off...
CVE-2018-6664
- EPSS 0.28%
- Published 25.05.2018 13:29:00
- Last modified 21.11.2024 04:11:04
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.
CVE-2017-3948
- EPSS 0.29%
- Published 23.06.2017 13:29:00
- Last modified 20.04.2025 01:37:25
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing sess...
CVE-2016-8012
- EPSS 0.04%
- Published 14.03.2017 22:59:00
- Last modified 20.04.2025 01:37:25
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get...
CVE-2016-3984
- EPSS 0.29%
- Published 08.04.2016 15:59:10
- Last modified 12.04.2025 10:46:40
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Pa...
CVE-2015-2760
- EPSS 0.19%
- Published 27.03.2015 14:59:10
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-2759
- EPSS 0.12%
- Published 27.03.2015 14:59:09
- Last modified 12.04.2025 10:46:40
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1)...