VendorsMcAfeedata_loss_prevention_endpointany version
Vulnerabilities

McAfee Data Loss Prevention Endpoint (DLPe) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2018-6664
SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 - Application Protections Bypass vulnerability
Published 2018-05-25 · Modified
8.8EPSS 0.007
CVE-2021-31849
Data Loss Prevention (DLP) ePO extension - SQL injection
Published 2021-11-01 · Modified
8.4EPSS 0.011
CVE-2021-31848
Data Loss Prevention (DLP) ePO extension - Cross site scripting (XSS)
Published 2021-11-01 · Modified
8.4EPSS 0.008
CVE-2021-31844
Local Privilege Escalation in McAfee DLP Endpoint for Windows
Published 2021-09-17 · Modified
8.2EPSS 0.004
CVE-2019-3622
DLP Endpoint log file redirection to arbitrary locations
Published 2019-07-24 · Modified
8.2EPSS 0.003
CVE-2018-6689
Data Loss Prevention Endpoint (DLPe) - Authentication Bypass vulnerability
Published 2018-10-03 · Modified
7.8EPSS 0.004
CVE-2016-8012
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get.
Published 2017-03-14 · Modified
7.8EPSS 0.003
CVE-2021-23887
Privilege escalation in McAfee DLP Endpoint for Windows
Published 2021-04-15 · Modified
7.8EPSS 0.002
CVE-2018-6683
- Data Loss Prevention (DLP) for Windows - Exploiting Incorrectly Configured Access Control Security Levels vulnerability
Published 2018-07-23 · Modified
7.4EPSS 0.003
CVE-2015-1305
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
Published 2015-02-06 · Modified
6.91 PoCEPSS 0.009
CVE-2015-2759
Multiple cross-site request forgery (CSRF) vulnerabilities in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allow remote attackers to hijack the authentication of users for requests that (1) obtain sensitive information or (2) modify the database via unspecified vectors.
Published 2015-03-27 · Modified
6.8EPSS 0.008
CVE-2019-3621
DLP Endpoint Windows lock screen bypass with physical access
Published 2019-07-25 · Modified
6.8EPSS 0.003
CVE-2015-2758
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL.
Published 2015-03-27 · Modified
6.5EPSS 0.015
CVE-2015-1616
SQL injection vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated ePO users to execute arbitrary SQL commands via unspecified vectors.
Published 2015-02-17 · Modified
6.5EPSS 0.014
CVE-2022-2330
XXE vulnerability in DLP Endpoint for Windows
Published 2022-08-30 · Modified
6.5EPSS 0.009
CVE-2019-3595
DLP Endpoint ePO extension not sanitizing CSV exports
Published 2019-07-24 · Modified
6.5EPSS 0.007
CVE-2019-3591
DLP Endpoint ePO extension vulnerable to XSS
Published 2019-07-24 · Modified
6.1EPSS 0.008
CVE-2019-3633
Buffer overflow in DLP Endpoint for Windows
Published 2019-08-21 · Modified
5.5EPSS 0.003
CVE-2019-3634
Buffer overflow in DLP Endpoint for Windows
Published 2019-08-21 · Modified
5.5EPSS 0.002
CVE-2021-23886
Local Denial of Service in McAfee DLP Endpoint for Windows
Published 2021-04-15 · Modified
5.5EPSS 0.002
CVE-2016-3984
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
Published 2016-04-08 · Modified
5.11 PoCEPSS 0.011
CVE-2015-2757
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors.
Published 2015-03-27 · Modified
4.0EPSS 0.014
CVE-2015-1618
The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to obtain sensitive password information via a crafted URL.
Published 2015-02-17 · Modified
4.0EPSS 0.013
CVE-2015-1617
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-02-17 · Modified
3.5EPSS 0.011
CVE-2015-2760
Cross-site scripting (XSS) vulnerability in the ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-03-27 · Modified
3.5EPSS 0.011