Page 2 of 30 results (0.006 seconds)

CVSS: 3.3EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 registra los identificadores de las sesione, lo que permite a usuarios locales obtener información sensible mediante la lectura del registro de auditoria. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remote attackers to obtain sensitive information via unspecified vectors. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 no deshabilita la configuración de autocompletado para la contraseña y otros campos, lo que permite a atacantes remotos obtener información sensible a través de vectores no especificados. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 no incluye el indicador HTTPOnly en una cabecera Set-Cookie para la cookie de la sesión, lo que facilita a atacantes remotos obtener información potencialmente sensible a través del acceso de secue... • http://www.securityfocus.com/bid/70823 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to bypass intended restriction on unspecified functionality via unknown vectors. McAfee Network Data Loss Prevention (NDLP) anterior a 9.2.2 permite a usuarios locales evadir las restricciones sobre una funcionalidad no especificada a través de vectores desconocidos. • https://kc.mcafee.com/corporate/index?page=content&id=SB10044 •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network ports. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a atacantes remotos obtener información sensible a través de vectores relacionados con puertos de la red abiertos. • http://www.securityfocus.com/bid/70815 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 5.4EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — Cross-site scripting (XSS) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 9.8EPSS: 3%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a atacantes remotos ejecutar código arbitrario a través de vectores relacionados con la redirección ICMP. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 •

CVSS: 9.1EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information, affect integrity, or cause a denial of service via unknown vectors, related to simultaneous logins. Vulnerabilidad no especificada en McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a atacantes remotos obtener información sensible, afectar la integridad o causar una denegación de servicio a través de vectores desconocidos, relacionado con inicios de se... • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 •

CVSS: 5.5EPSS: 0%CPEs: 3EXPL: 0

29 Oct 2014 — Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to read arbitrary files via unknown vectors. Vulnerabilidad no especificada en McAfee Network Data Loss Prevention (NDLP) anterior a 9.2.2 permite a usuarios locales leer ficheros arbitrarios a través de vectores desconocidos. • https://kc.mcafee.com/corporate/index?page=content&id=SB10044 •

CVSS: 3.3EPSS: 0%CPEs: 4EXPL: 0

29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a usuarios locales obtener información sensible mediante la lectura de una traza de pilas Java. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •