VYPR

McAfee Agent

by McAfee

CVEs (12)

  • CVE-2022-1257Apr 14, 2022
    risk 0.03cvss epss 0.00

    Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

  • CVE-2020-7343Jan 18, 2021
    risk 0.00cvss epss 0.00

    Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.

  • CVE-2020-7311Sep 10, 2020
    risk 0.00cvss epss 0.00

    Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.

  • CVE-2019-3613Jun 10, 2020
    risk 0.00cvss epss 0.00

    DLL Search Order Hijacking vulnerability in McAfee Agent (MA) prior to 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.

  • CVE-2020-7253Mar 12, 2020
    risk 0.00cvss epss 0.00

    Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.

  • CVE-2019-3598Feb 28, 2019
    risk 0.00cvss epss 0.00

    Buffer Access with Incorrect Length Value in McAfee Agent (MA) 5.x allows remote unauthenticated users to potentially cause a denial of service via specifically crafted UDP packets.

  • CVE-2018-6707Dec 13, 2018
    risk 0.00cvss epss 0.00

    Denial of Service through Resource Depletion vulnerability in the agent in non-Windows McAfee Agent (MA) 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to cause DoS, unexpected behavior, or potentially unauthorized code execution via knowledge of the internal trust…

  • CVE-2018-6706Dec 12, 2018
    risk 0.00cvss epss 0.00

    Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.

  • CVE-2018-6704Dec 12, 2018
    risk 0.00cvss epss 0.00

    Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.

  • CVE-2018-6703Dec 11, 2018
    risk 0.00cvss epss 0.03

    Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging…

  • CVE-2015-7237Sep 18, 2015
    risk 0.00cvss epss 0.00

    Directory traversal vulnerability in the remote log viewing functionality in McAfee Agent (MA) 5.x before 5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2009-5115Aug 22, 2012
    risk 0.00cvss epss 0.00

    McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenticated users to overwrite arbitrary files by accessing a report-writing ActiveX control COM object.