CVE-2014-8536
https://notcve.org/view.php?id=CVE-2014-8536
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading unspecified error messages. McAfee Network Data Loss Prevention (NDLP) anterior a 9.2.2 permite a usuarios locales obtener información sensible mediante la lectura de mensajes de error no especificados. • http://www.securityfocus.com/bid/70840 https://exchange.xforce.ibmcloud.com/vulnerabilities/98427 https://kc.mcafee.com/corporate/index?page=content&id=SB10044 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-8526
https://notcve.org/view.php?id=CVE-2014-8526
McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information by reading a Java stack trace. McAfee Network Data Loss Prevention (NDLP) anterior a 9.3 permite a usuarios locales obtener información sensible mediante la lectura de una traza de pilas Java. • https://kc.mcafee.com/corporate/index?page=content&id=SB10053 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-6064
https://notcve.org/view.php?id=CVE-2014-6064
The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors. La pestaña Accounts en la interfaz de usuario de administración en McAfee Web Gateway (MWG) anterior a 7.3.2.9 y 7.4.x anterior a 7.4.2 permite a usuarios remotos autenticados obtener las contraseñas de usuarios en hash a través de vectores no especificados. • http://www.securitytracker.com/id/1030675 https://exchange.xforce.ibmcloud.com/vulnerabilities/95690 https://kc.mcafee.com/corporate/index?page=content&id=SB10080 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2014-2390
https://notcve.org/view.php?id=CVE-2014-2390
Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors. Vulnerabilidad de CSRF en el módulo User Management en McAfee Network Security Manager (NSM) anterior a 6.1.15.39 7.1.5.x anterior a 7.1.5.15, 7.1.15.x anterior a 7.1.15.7, 7.5.x anterior a 7.5.5.9, y 8.x anterior a 8.1.7.3 permite a atacantes remotos secuestrar la autenticación de usuarios para solicitudes que modifican las cuentas de los usuarios a través de vectores no especificados. • http://www.securitytracker.com/id/1030674 https://kc.mcafee.com/corporate/index?page=content&id=SB10081 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2014-2588 – McAfee Asset Manager 6.6 - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2014-2588
Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter. Vulnerabilidad de salto de directorio en servlet/downloadReport en McAfee Asset Manager 6.6 permite a usuarios remotos autenticados leer archivos arbitrarios a través de un .. (punto punto) en el parámetro reportFileName. • https://www.exploit-db.com/exploits/32368 http://packetstormsecurity.com/files/125775/McAfee-Cloud-SSO-Asset-Manager-Issues.html http://seclists.org/fulldisclosure/2014/Mar/325 http://www.exploit-db.com/exploits/32368 http://www.osvdb.org/104633 http://www.securityfocus.com/bid/66302 http://www.securitytracker.com/id/1029927 https://exchange.xforce.ibmcloud.com/vulnerabilities/91930 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •