Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 9.7% | 💥 Exploit | Mcafee Security CenterMcafee Securitycenter AgentMcafee Virusscan | 10/5/2007 | 16/6/2026 | Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument. | |
| Modificada | Alta (7.9) | 2.6% | — | Mcafee Virusscan Enterprise | 19/4/2007 | 16/6/2026 | Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters. | |
| Modificada | Alta (7.5) | 1.9% | — | Mcafee Virusscan Enterprise | 20/3/2007 | 16/6/2026 | McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password protection via the UIP value in (1) HKEY_LOCAL_MACHINE\SOFTWARE\McAfee\DesktopProtection or (2) HKEY_LOCAL_MACHINE\SOFTWARE\Network Associates\TVD\VirusScan… | |
| Modificada | Media (4.6) | 0.41% | — | Mcafee Virusscan | 14/12/2006 | 16/6/2026 | Untrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environment variable, which allows local users to load arbitrary ELF DSO libraries and execute arbitrary code by installing malicious libraries in that directory. | |
| Modificada | Media (5) | 1.8% | — | Mcafee Internet Security SuiteMcafee Network AgentMcafee Personal Firewall PlusMcafee Virusscan | 20/10/2006 | 16/6/2026 | McAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus, and VirusScan, allows remote attackers to cause a denial of service (agent crash) via a long packet, possibly because of an invalid string position field value. NOTE:… | |
| Modificada | Baja (3.7) | 0.36% | — | Mcafee Scan EngineMcafee Virusscan Enterprise | 19/9/2006 | 16/6/2026 | The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button, possibly due to an interface-related… | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands… | |
| Modificada | Baja (2.1) | 0.38% | — | Mcafee Virusscan | 13/7/2006 | 16/6/2026 | Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields. | |
| Modificada | Alta (7.2) | 0.99% | 💥 Exploit | Mcafee Common Management AgentMcafee Virusscan Enterprise | 23/12/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path. | |
| Modificada | Media (5) | 2.3% | — | Mcafee Mcinsctl.dllMcafee Virusscan Security Center | 21/12/2005 | 16/6/2026 | The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object. | |
| Modificada | Alta (7.2) | 0.39% | — | Mcafee Virusscan | 14/9/2004 | 16/6/2026 | McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges. | |
| Modificada | Media (6.9) | 0.33% | — | Mcafee Virusscan | 31/12/2002 | 16/6/2026 | McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs. | |
| Modificada | Media (5) | 5.8% | — | Mcafee Asap Virusscan | 11/7/2001 | 16/6/2026 | Directory traversal vulnerability in McAfee ASaP VirusScan agent 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request. | |
| Modificada | Media (4.6) | 0.47% | — | Mcafee Virusscan | 9/1/2001 | 16/6/2026 | The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory. | |
| Modificada | Baja (2.1) | 0.43% | — | Network Associates NetshieldNetwork Associates Virusscan | 11/7/2000 | 16/6/2026 | The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse. | |
| Modificada | Baja (2.1) | 0.40% | — | Mcafee Virusscan | 8/6/2000 | 16/6/2026 | Mcafee VirusScan 4.03 does not properly restrict access to the alert text file before it is sent to the Central Alert Server, which allows local users to modify alerts in an arbitrary fashion. | |
| Modificada | Alta (7.2) | 1.2% | 💥 Exploit | Mcafee VirusscanSymantec Norton Antivirus | 22/12/1999 | 16/6/2026 | The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection. | |
| Modificada | Media (5.1) | 1.5% | — | Network Associates Virusscan | 5/5/1999 | 16/6/2026 | NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly. |