|
266071
|
7.8 |
HIGH
Local
|
mcafee
|
data_loss_prevention_endpoint
|
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8012
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266072
|
6.1 |
MEDIUM
Network
|
intel_security_mcafee
|
endpoint_security_web_control
|
Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.
|
CWE-79
Cross-site Scripting
|
CVE-2016-8011
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266073
|
7.8 |
HIGH
Local
|
mcafee
|
application_control endpoint_security
|
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local securit…
|
CWE-284
Improper Access Control
|
CVE-2016-8010
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266074
|
7.8 |
HIGH
Local
|
mcafee
|
application_control
|
Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code executi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8009
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266075
|
8.8 |
HIGH
Local
|
mcafee
|
security_scan_plus
|
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8008
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266076
|
6.3 |
MEDIUM
Local
|
mcafee
|
host_intrusion_prevention_services
|
Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific condi…
|
CWE-284
Improper Access Control
|
CVE-2016-8007
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266077
|
6.5 |
MEDIUM
Network
|
mcafee
|
email_gateway
|
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a for…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8005
|
2024-11-21 11:58 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266078
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
|
CWE-89
SQL Injection
|
CVE-2016-7789
|
2024-11-21 11:58 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266079
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
CWE-89
SQL Injection
|
CVE-2016-7788
|
2024-11-21 11:58 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266080
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the s…
|
CWE-89
SQL Injection
|
CVE-2016-7784
|
2024-11-21 11:58 |
2017-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|