← Vulnerability feed

Vulnerability record · CVE-2006-5271 · published 12 July 2007

CVE-2006-5271: Mcafee e-business server vulnerability

MMcafee · E Business Server

Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption.

7.6 CVSS 2.0 High EPSS 4.0% · top 9.8%
7.6CVSS 2.0 base score
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Integer underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and earlier allows remote attackers to execute arbitrary code via a crafted UDP packet, which causes stack corruption.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5271 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5156McAfee ePolicy Orchestrator and ProtectionPilot buffer overflow via long source headerMcAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg…EPSS 74%analysed9.3CVE-2007-2957Mcafee e-business server vulnerabilityInteger overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute…EPSS 6.2%9.3CVE-2007-1498Mcafee epolicy orchestrator vulnerabilityMultiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy …EPSS 7.7%8.8CVE-2008-0127Mcafee e-business server memory buffer overflow vulnerabilityThe administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute a…EPSS 8.6%7.6CVE-2006-5273Mcafee common management agent vulnerabilityHeap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.4…EPSS 6.3%7.6CVE-2006-5274Mcafee common management agent vulnerabilityInteger overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows …EPSS 5.0%7.5CVE-2006-5272Mcafee common management agent vulnerabilityStack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.…EPSS 3.6%5.0CVE-2007-2151Mcafee e-business server vulnerabilityThe administration server in McAfee e-Business Server before 8.1.1 and 8.5.x before 8.5.2 allows remote attackers to cause a denial of service (servi…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2006-5271), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.