![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8536
https://notcve.org/view.php?id=CVE-2014-8536
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages. McAfee Network Data Loss Prevention (NDLP) anterior a 9.2.2 permite a usuarios locales obtener información sensible mediante la lectura de mensajes de error no especificados. • http://www.securityfocus.com/bid/70840 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8526
https://notcve.org/view.php?id=CVE-2014-8526
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a usuarios locales obtener información sensible mediante la lectura de una traza de pilas Java. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8529
https://notcve.org/view.php?id=CVE-2014-8529
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 stores the SSH key in cleartext, which allows local users to obtain sensitive information via unspecified vectors. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 almacena la clave SSH en texto plano, lo que permite a usuarios locales obtener información sensible a través de vectores no especificados. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-310: Cryptographic Issues •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8527
https://notcve.org/view.php?id=CVE-2014-8527
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password." McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a usuarios locales obtener información sensible y afectar la integridad a través de vectores relacionados con una 'contraseña de texto plano.' • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-255: Credentials Management Errors •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8523
https://notcve.org/view.php?id=CVE-2014-8523
29 Oct 2014 — Cross-site request forgery (CSRF) vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. Vulnerabilidad de CSRF en McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a atacantes remotos secuestrar la autenticación de victimas no especificadas a través de vectores desconocidos. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-352: Cross-Site Request Forgery (CSRF) •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8533
https://notcve.org/view.php?id=CVE-2014-8533
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to execute arbitrary code via vectors related to ICMP redirection. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a atacantes remotos ejecutar código arbitrario a través de vectores relacionados con la redirección ICMP. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8522
https://notcve.org/view.php?id=CVE-2014-8522
29 Oct 2014 — The MySQL database in McAfee Network Data Loss Prevention (NDLP) before 9.3 does not require a password, which makes it easier for remote attackers to obtain access. La base de datos MySQL en McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 no requiere una contraseña, lo que facilita a atacantes remotos obtener el acceso. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-287: Improper Authentication •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8525
https://notcve.org/view.php?id=CVE-2014-8525
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 no incluye el indicador HTTPOnly en una cabecera Set-Cookie para la cookie de la sesión, lo que facilita a atacantes remotos obtener información potencialmente sensible a través del acceso de secue... • http://www.securityfocus.com/bid/70823 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8524
https://notcve.org/view.php?id=CVE-2014-8524
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remote attackers to obtain sensitive information via unspecified vectors. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 no deshabilita la configuración de autocompletado para la contraseña y otros campos, lo que permite a atacantes remotos obtener información sensible a través de vectores no especificados. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-8528
https://notcve.org/view.php?id=CVE-2014-8528
29 Oct 2014 — McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 registra los identificadores de las sesione, lo que permite a usuarios locales obtener información sensible mediante la lectura del registro de auditoria. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •