Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

613 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.69%—Mcafee Epolicy Orchestrator13/2/201717/6/2026
Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.
ModificadaMedia (5.9)2.5%—Mcafee Agent13/2/201717/6/2026
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.
ModificadaMedia (4.4)0.32%—Mcafee Security Information AND Event Management5/1/201717/6/2026
Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM users' information including user passwords without supplying the current…
ModificadaAlta (8.1)12%—Libexpat Project LibexpatCanonical Ubuntu LinuxMcafee Policy AuditorPython30/6/201617/6/2026
The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.
ModificadaCrítica (9.8)7.0%—HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+159/6/201617/6/2026
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
ModificadaAlta (7.5)14%—HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+79/6/201617/6/2026
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
ModificadaCrítica (9.8)13%—Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+1026/5/201617/6/2026
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
ModificadaAlta (7.8)3.2%—Debian LinuxApple Iphone OSApple MAC OS XApple Tvos+1020/5/201617/6/2026
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
ModificadaMedia (5.5)7.3%💥 ExploitApple Iphone OSApple MAC OS XApple TvosApple Watchos+1020/5/201617/6/2026
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
ModificadaMedia (5.5)6.9%💥 ExploitCanonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+1020/5/201617/6/2026
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
ModificadaMedia (5.5)4.4%—Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+1020/5/201617/6/2026
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
ModificadaMedia (5.5)4.3%—Canonical Ubuntu LinuxDebian LinuxApple Iphone OSApple MAC OS X+1020/5/201617/6/2026
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
ModificadaAlta (7.8)4.6%—Canonical Ubuntu LinuxApple Iphone OSApple MAC OS XApple Tvos+1020/5/201617/6/2026
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
ModificadaMedia (5.5)2.6%—Apple Iphone OSApple MAC OS XApple TvosApple Watchos+1020/5/201617/6/2026
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
ModificadaAlta (7.5)9.8%💥 ExploitMcafee Livesafe5/5/201617/6/2026
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable.
ModificadaBaja (3)2.3%💥 ExploitMcafee Virusscan EnterpriseMicrosoft Windows5/5/201617/6/2026
The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles.
ModificadaMedia (5.1)1.1%💥 ExploitMcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+38/4/201617/6/2026
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before…
ModificadaAlta (7.5)0.61%—Mcafee Advanced Threat Defense8/4/201617/6/2026
McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.
ModificadaMedia (6.1)1.0%—Mcafee Email Gateway6/4/201617/6/2026
Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.
ModificadaAlta (8.1)6.5%—Apple SafariApple Iphone OSApple MAC OS XApple Tvos+1124/3/201617/6/2026
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
ModificadaAlta (8.8)0.55%—Mcafee Vulnerability Manager1/2/201617/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before 7.5.10 allow remote attackers to hijack the authentication of administrators for requests that have unspecified impact via unknown vectors.
ModificadaAlta (7.5)1.2%—Mcafee File Lock29/1/201617/6/2026
Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers to cause a denial of service (system crash) via a long vault GUID in an ioctl call.
ModificadaCrítica (9.1)1.5%—Mcafee File Lock29/1/201617/6/2026
McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large VERIFY_INFORMATION.Length value in an IOCTL_DISK_VERIFY ioctl call.
ModificadaMedia (6.6)2.3%—Microsoft WindowsMcafee Application Control12/1/201617/6/2026
The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges…
ModificadaAlta (8.3)2.7%—Mcafee Epolicy Orchestrator8/1/201617/6/2026
Intel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remote attackers to execute arbitrary code via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.