Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
613 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.69% | — | Mcafee Epolicy Orchestrator | 13/2/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation. | |
| Modificada | Media (5.9) | 2.5% | — | Mcafee Agent | 13/2/2017 | 17/6/2026 | Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated. | |
| Modificada | Media (4.4) | 0.32% | — | Mcafee Security Information AND Event Management | 5/1/2017 | 17/6/2026 | Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current… | |
| Modificada | Alta (8.1) | 12% | — | Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython | 30/6/2016 | 17/6/2026 | The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716. | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+15 | 9/6/2016 | 17/6/2026 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | |
| Modificada | Alta (7.5) | 14% | — | HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+7 | 9/6/2016 | 17/6/2026 | The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName. | |
| Modificada | Crítica (9.8) | 13% | — | Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+10 | 26/5/2016 | 17/6/2026 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
| Modificada | Alta (7.8) | 3.2% | — | Debian LinuxApple Iphone OSApple MAC OS XApple Tvos+10 | 20/5/2016 | 17/6/2026 | Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. | |
| Modificada | Media (5.5) | 7.3% | 💥 Exploit | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+10 | 20/5/2016 | 17/6/2026 | The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Media (5.5) | 6.9% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Media (5.5) | 4.4% | — | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document. | |
| Modificada | Media (5.5) | 4.3% | — | Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+10 | 20/5/2016 | 17/6/2026 | Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document. | |
| Modificada | Alta (7.8) | 4.6% | — | Canonical Ubuntu LinuxApple Iphone OSApple MAC OS XApple Tvos+10 | 20/5/2016 | 17/6/2026 | Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document. | |
| Modificada | Media (5.5) | 2.6% | — | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+10 | 20/5/2016 | 17/6/2026 | The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Mcafee Livesafe | 5/5/2016 | 17/6/2026 | Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable. | |
| Modificada | Baja (3) | 2.3% | 💥 Exploit | Mcafee Virusscan EnterpriseMicrosoft Windows | 5/5/2016 | 17/6/2026 | The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles. | |
| Modificada | Media (5.1) | 1.1% | 💥 Exploit | Mcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+3 | 8/4/2016 | 17/6/2026 | The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before… | |
| Modificada | Alta (7.5) | 0.61% | — | Mcafee Advanced Threat Defense | 8/4/2016 | 17/6/2026 | McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process. | |
| Modificada | Media (6.1) | 1.0% | — | Mcafee Email Gateway | 6/4/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email. | |
| Modificada | Alta (8.1) | 6.5% | — | Apple SafariApple Iphone OSApple MAC OS XApple Tvos+11 | 24/3/2016 | 17/6/2026 | The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document. | |
| Modificada | Alta (8.8) | 0.55% | — | Mcafee Vulnerability Manager | 1/2/2016 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before 7.5.10 allow remote attackers to hijack the authentication of administrators for requests that have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Mcafee File Lock | 29/1/2016 | 17/6/2026 | Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers to cause a denial of service (system crash) via a long vault GUID in an ioctl call. | |
| Modificada | Crítica (9.1) | 1.5% | — | Mcafee File Lock | 29/1/2016 | 17/6/2026 | McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large VERIFY_INFORMATION.Length value in an IOCTL_DISK_VERIFY ioctl call. | |
| Modificada | Media (6.6) | 2.3% | — | Microsoft WindowsMcafee Application Control | 12/1/2016 | 17/6/2026 | The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges… | |
| Modificada | Alta (8.3) | 2.7% | — | Mcafee Epolicy Orchestrator | 8/1/2016 | 17/6/2026 | Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. |