Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

McAfee — Vulnerabilities & Security Advisories 106

Browse all 106 CVE security advisories affecting McAfee. AI-powered Chinese analysis, POCs, and references for each vulnerability.

McAfee operates as a prominent cybersecurity vendor, primarily providing endpoint protection and threat intelligence services to enterprise and consumer markets. Its software portfolio, encompassing antivirus solutions and network security appliances, has historically been susceptible to critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These defects often stem from complex codebases and legacy components within its extensive suite of security tools. Notable incidents include significant data breaches affecting customer information and internal systems, highlighting risks associated with centralized security infrastructure. With over one hundred recorded Common Vulnerabilities and Exposures, the company faces ongoing scrutiny regarding its patch management and secure development practices. These recurring issues underscore the challenges inherent in maintaining robust security postures for large-scale, widely deployed enterprise software, necessitating rigorous third-party audits and continuous vulnerability remediation to mitigate potential exploitation by threat actors.

CVE IDTitleCVSSSeverityPublished
CVE-2018-6677 McAfee Web Gateway (MWG) - Directory Traversal vulnerability — McAfee Web Gateway (MWG) 7.2 -2018-07-23
CVE-2018-6678 McAfee Web Gateway (MWG) - Configuration/Environment manipulation vulnerability — McAfee Web Gateway (MWG) 7.2 -2018-07-23
CVE-2018-6681 SB10244 - Network Security Management (NSM) - Abuse of Functionality vulnerability — Network Security Management (NSM) 5.4 -2018-07-17
CVE-2018-6667 McAfee Web Gateway - Authentication Bypass vulnerability — Web Gateway 9.8 -2018-06-26
CVE-2018-6671 SB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability — ePolicy Orchestrator (ePO) 6.5 -2018-06-15
CVE-2018-6672 SB10240 - ePolicy Orchestrator (ePO) - Information disclosure vulnerablity — ePolicy Orchestrator (ePO) 6.5 -2018-06-15
CVE-2017-3907 McAfee Threat Intelligence Exchange (TIE) Server - Code Injection vulnerability — Threat Intelligence Exchange (TIE) Server 8.8 -2018-06-13
CVE-2017-3936 McAfee ePolicy Orchestrator (ePO) - OS Command Injection vulnerability — ePolicy Orchestrator (ePO) 9.8 -2018-06-13
CVE-2017-3968 McAfee Network Security Management (NSM) and Network Data Loss Prevention (NDLP)- Password recovery exploitation vulnerability — Network Security Management (NSM) 9.1 -2018-06-13
CVE-2017-3960 McAfee Network Security Management (NSM) - Exploitation of Authorization vulnerability — Network Security Management (NSM) 8.8 -2018-06-12
CVE-2017-3962 McAfee Network Security Management (NSM) - Password recovery exploitation vulnerability — Network Security Management (NSM) 9.1 -2018-06-12
CVE-2018-6670 External Entity Attack vulnerability in McAfee Common UI (CUI) — Common UI (CUI) 6.5 -2018-06-07
CVE-2018-6662 SB10232 - McAfee Management of Native Encryption (MNE) - Privilege Escalation vulnerability — McAfee Management of Native Encryption (MNE) 7.8 -2018-06-05
CVE-2017-3961 SB10192 - Network Security Management (NSM) - Cross-Site Scripting (XSS) vulnerability — Network Security Management (NSM) 5.4 -2018-05-25
CVE-2018-6664 SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 - Application Protections Bypass vulnerability — Data Loss Prevention (DLP) Endpoint 8.8 -2018-05-25
CVE-2017-3964 SB10192 - Network Security Management (NSM) - Reflective Cross-Site Scripting (XSS) vulnerability — Network Security Management (NSM) 5.4 -2018-04-04
CVE-2017-3965 SB10192 - Network Security Management (NSM) - Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability — Network Security Management (NSM) 8.8 -2018-04-04
CVE-2017-3966 SB10192 - Network Security Management (NSM) - Exploitation of session variables, resource IDs and other trusted credentials vulnerability — Network Security Management (NSM) 5.4 -2018-04-04
CVE-2017-3967 SB10192 - Network Security Management (NSM) - Target influence via framing vulnerability — Network Security Management (NSM) 7.2 -2018-04-04
CVE-2017-3969 SB10192 - Network Security Management (NSM) - Abuse of communication channels vulnerability — Network Security Management (NSM) 5.9 -2018-04-04
CVE-2017-3971 SB10192 - Network Security Management (NSM) - Cryptanalysis vulnerability — Network Security Management (NSM) 6.5 -2018-04-04
CVE-2017-3972 SB10192 - Network Security Management (NSM) - Infrastructure-based foot printing vulnerability — Network Security Management (NSM) 8.8 -2018-04-03
CVE-2017-4028 SB10193 - consumer and corporate products - Maliciously misconfigured registry vulnerability — McAfee Anti-Virus Plus (AVP) 4.4 -2018-04-03
CVE-2018-6659 SB10228 ePO Reflected Cross-Site Scripting vulnerability — ePolicy Orchestrator (ePO) 5.4 -2018-04-02
CVE-2018-6660 SB10228 ePO Directory Traversal vulnerability — ePolicy Orchestrator (ePO) 2.7 -2018-04-02
CVE-2018-6661 TS102801 True Key DLL Side-Loading vulnerability — True Key 7.8 -2018-04-02
CVE-2017-3933 McAfee Network Data Loss Prevention 跨站脚本漏洞 — Network Data Loss Prevention 5.4 -2017-10-31
CVE-2017-3934 McAfee Network Data Loss Prevention server 安全漏洞 — Network Data Loss Prevention 5.9 -2017-10-31
CVE-2017-3935 McAfee Network Data Loss Prevention 安全漏洞 — Network Data Loss Prevention 7.5 -2017-10-31
CVE-2017-3897 McAfee Live Safe和McAfee Security Scan Plus 代码注入漏洞 — Live Safe 9.8 -2017-09-01

This page lists every published CVE security advisory associated with McAfee. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.