|
219501
|
6.5 |
MEDIUM
Network
|
mcafee
|
advanced_threat_defense
|
Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via …
|
CWE-22
Path Traversal
|
CVE-2019-3662
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219502
|
8.8 |
HIGH
Network
|
mcafee
|
advanced_threat_defense
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute database comm…
|
CWE-89
SQL Injection
|
CVE-2019-3661
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219503
|
6.5 |
MEDIUM
Network
|
mcafee
|
data_loss_prevention
|
Unprotected Transport of Credentials in ePO extension in McAfee Data Loss Prevention 11.x prior to 11.4.0 allows remote attackers with access to the network to collect login details to the LDAP serve…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2019-3640
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219504
|
8.8 |
HIGH
Network
|
mcafee
|
advanced_threat_defense
|
Improper Neutralization of HTTP requests in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to execute commands on the server remotely via carefully constructed…
|
NVD-CWE-noinfo
|
CVE-2019-3660
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219505
|
8.8 |
HIGH
Network
|
mcafee
|
advanced_threat_defense
|
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using the atduser credenti…
|
CWE-269
Improper Privilege Management
|
CVE-2019-3651
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219506
|
6.5 |
MEDIUM
Network
|
mcafee
|
advanced_threat_defense
|
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to the atduser credentials via carefully constructed GET …
|
NVD-CWE-noinfo
|
CVE-2019-3650
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219507
|
6.5 |
MEDIUM
Network
|
mcafee
|
advanced_threat_defense
|
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST req…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2019-3649
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219508
|
6.5 |
MEDIUM
Adjacent
|
zte
|
zxhn_h108n_firmware
|
All versions up to V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perfor…
|
NVD-CWE-noinfo
|
CVE-2019-3420
|
2024-11-21 13:42 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219509
|
4.5 |
MEDIUM
Network
|
mcafee
|
threat_intelligence_exchange_server
|
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data …
|
NVD-CWE-noinfo
|
CVE-2019-3641
|
2024-11-21 13:42 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219510
|
6.7 |
MEDIUM
Local
|
mcafee
|
anti-virus_plus internet_security total_protection
|
A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious fi…
|
CWE-426
Untrusted Search Path
|
CVE-2019-3648
|
2024-11-21 13:42 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|