VendorsMcAfeeweb_gatewayall versions
Vulnerabilities

McAfee Web Gateway

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2016-4448
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
Published 2016-06-09 · Modified
10.0EPSS 0.070
CVE-2018-18311
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
Published 2018-12-07 · Modified
9.8EPSS 0.117
CVE-2019-9169
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
Published 2019-02-26 · Modified
9.8EPSS 0.047
CVE-2019-3638
Web Gateway (MWG) - Reflected Cross Site Scripting vulnerability
Published 2019-09-12 · Modified
9.6EPSS 0.019
CVE-2016-1834
Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
Published 2016-05-20 · Modified
9.3EPSS 0.046
CVE-2021-23885
Privilege escalation vulnerability in McAfee Web Gateway (MWG) UI
Published 2021-02-17 · Modified
9.0EPSS 0.011
CVE-2020-7293
Web Gateway (MWG) - Privilege Escalation vulnerability
Published 2020-09-15 · Modified
9.0EPSS 0.007
CVE-2016-1762
The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Published 2016-03-24 · Modified
8.1EPSS 0.065
CVE-2021-3156
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
Published 2021-01-26 · Analyzed
7.8KEV2 PoCEPSS 1.000
CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.874
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.816
CVE-2019-9511
Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.595
CVE-2019-9517
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.279
CVE-2019-9518
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.254
CVE-2016-1840
Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.
Published 2016-05-20 · Modified
7.8EPSS 0.032
CVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
Published 2017-06-19 · Modified
7.83 PoCEPSS 0.027
CVE-2019-9516
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.5EPSS 0.563
CVE-2016-4447
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
Published 2016-06-09 · Modified
7.5EPSS 0.140
CVE-2019-3643
MWG scanners updated to address CVE-2019-9511
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2019-3644
MWG scanners updated to address CVE-2019-9517
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2021-3450
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Published 2021-03-25 · Modified
7.4EPSS 0.183
CVE-2019-3639
MWG UI: Cross-Frame Scripting vulnerability
Published 2019-08-14 · Modified
7.1EPSS 0.012
CVE-2019-3635
MWG Proxy: Cross-Frame Scripting vulnerability
Published 2019-08-14 · Modified
6.5EPSS 0.012
CVE-2022-1254
SWG URL redirection vulnerability
Published 2022-04-20 · Modified
6.1EPSS 0.008
CVE-2021-3449
NULL pointer deref in signature_algorithms processing
Published 2021-03-25 · Modified
5.9EPSS 0.635
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2020-7296
Web Gateway (MWG) - Privilege Escalation vulnerability
Published 2020-09-15 · Modified
5.7EPSS 0.004
CVE-2020-7297
Web Gateway (MWG) - Privilege Escalation vulnerability
Published 2020-09-15 · Modified
5.7EPSS 0.004
CVE-2016-1839
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Published 2016-05-20 · Modified
5.51 PoCEPSS 0.073
CVE-2016-1838
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Published 2016-05-20 · Modified
5.51 PoCEPSS 0.069
CVE-2016-1837
Multiple use-after-free vulnerabilities in the (1) htmlPArsePubidLiteral and (2) htmlParseSystemiteral functions in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allow remote attackers to cause a denial of service via a crafted XML document.
Published 2016-05-20 · Modified
5.5EPSS 0.044
CVE-2016-1836
Use-after-free vulnerability in the xmlDictComputeFastKey function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service via a crafted XML document.
Published 2016-05-20 · Modified
5.5EPSS 0.043
CVE-2016-1833
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
Published 2016-05-20 · Modified
5.5EPSS 0.026
CVE-2019-6454
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).
Published 2019-03-17 · Modified
5.5EPSS 0.020
CVE-2012-2212
McAfee Web Gateway 7.0 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher did not provide configuration details for the vulnerable system, and the observed behavior might be consistent with a configuration that was (perhaps inadvertently) designed to allow access based on Host HTTP headers
Published 2012-04-28 · Modified
5.0EPSS 0.014
CVE-2020-7295
Web Gateway (MWG) - Privilege Escalation vulnerability
Published 2020-09-15 · Modified
4.6EPSS 0.005
CVE-2020-7294
Web Gateway (MWG) - Privilege Escalation vulnerability
Published 2020-09-15 · Modified
4.6EPSS 0.004
CVE-2020-7292
Web Gateway (MWG) - Inappropriate Encoding for output context
Published 2020-07-15 · Modified
4.3EPSS 0.009
CVE-2014-2535
Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port.
Published 2014-03-18 · Modified
4.0EPSS 0.021
1 / 2Next →