← Vulnerability feed

Vulnerability record · CVE-2006-5273 · published 12 July 2007

CVE-2006-5273: Mcafee common management agent vulnerability

MMcafee · Common Management Agent

Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet.

7.6 CVSS 2.0 High EPSS 6.3% · top 6.6%
7.6CVSS 2.0 base score
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 through 3.6.0.453 allows remote attackers to execute arbitrary code via a crafted packet.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5156McAfee ePolicy Orchestrator and ProtectionPilot buffer overflow via long source headerMcAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg…EPSS 74%analysed9.3CVE-2007-2957Mcafee e-business server vulnerabilityInteger overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute…EPSS 6.2%9.3CVE-2007-1498Mcafee epolicy orchestrator vulnerabilityMultiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy …EPSS 7.7%8.8CVE-2008-0127Mcafee e-business server memory buffer overflow vulnerabilityThe administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of service (crash) and execute a…EPSS 8.6%7.6CVE-2006-5274Mcafee common management agent vulnerabilityInteger overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.5.5.438 allows …EPSS 5.0%7.6CVE-2006-5271Mcafee e-business server vulnerabilityInteger underflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.453 and ea…EPSS 4.0%7.5CVE-2006-5272Mcafee common management agent vulnerabilityStack-based buffer overflow in McAfee ePolicy Orchestrator 3.5 through 3.6.1, ProtectionPilot 1.1.1 and 1.5, and Common Management Agent (CMA) 3.6.0.…EPSS 3.6%7.2CVE-2005-4505Mcafee common management agent vulnerabilityUnquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privi…EPSS 0.99%

Source: NIST National Vulnerability Database (record CVE-2006-5273), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.