CVE-2013-4883
- EPSS 3.42%
- Published 22.07.2013 11:21:15
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceI...
CVE-2013-4882
- EPSS 1.1%
- Published 22.07.2013 11:21:15
- Last modified 11.04.2025 00:51:21
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid pa...
CVE-2013-0141
- EPSS 0.42%
- Published 01.05.2013 12:00:07
- Last modified 11.04.2025 00:51:21
Directory traversal vulnerability in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to upload arbitrary files via a crafted request over the Agent-Server communication channel, as demonstrated by writing...
CVE-2013-0140
- EPSS 3.29%
- Published 01.05.2013 12:00:07
- Last modified 11.04.2025 00:51:21
SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication ch...
- EPSS 0.16%
- Published 22.08.2012 10:42:05
- Last modified 11.04.2025 00:51:21
McAfee ePolicy Orchestrator (ePO) 4.6.1 and earlier allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information from arbitrary reporting panels, via a modified ID value in a console URL.
CVE-2008-1357
- EPSS 27.88%
- Published 17.03.2008 17:44:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash...
CVE-2006-5274
- EPSS 12.44%
- Published 12.07.2007 00:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows remote attackers to cause a denial of service (CMA Framework service crash) and possibly execute arbi...
CVE-2007-1498
- EPSS 27.84%
- Published 16.03.2007 22:19:00
- Last modified 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote at...
- EPSS 82.96%
- Published 05.10.2006 04:04:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
CVE-2004-0038
- EPSS 1.78%
- Published 14.06.2004 04:00:00
- Last modified 03.04.2025 01:03:51
McAfee ePolicy Orchestrator (ePO) 2.5.1 Patch 13 and 3.0 SP2a Patch 3 allows remote attackers to execute arbitrary commands via certain HTTP POST requests to the spipe/file handler on ePO TCP port 81.