pulsesecure kayıtları
pulsesecure üreticisine ait 93 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %3,2
- Silahlaştırılmış
- 5 · %5,4
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %9,7
- Yayından KEV’e ortanca
- 585 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')14
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-20 Improper Input Validation4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-352 Cross-Site Request Forgery (CSRF)3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
93 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
88Hemen | CVE-2019-11539Silahlaştırılmış | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 anivanti · connect secure · CWE-78 | Yüksek7,2 | KEV | %98,5 | 25 Nis 2019 |
68Bu hafta | CVE-2020-8218Silahlaştırılmış | A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code eivanti · connect secure · CWE-94 | Yüksek7,2 | KEV | %32,3 | 30 Tem 2020 |
62Bu hafta | CVE-2021-22900Silahlaştırılmış | A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administraivanti · connect secure · CWE-94 | Yüksek7,2 | KEV | %14,1 | 27 May 2021 |
60Bu hafta | CVE-2019-11477Kavram kanıtı | Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segslinux · linux kernel · CWE-190 | Yüksek7,5 | — | %98,7 | 18 Haz 2019 |
58Planlayın | CVE-2019-11478İstismar yok | SACK can cause extensive memory use via fragmented resend queuelinux · linux kernel · CWE-770 | Yüksek7,5 | — | %94,7 | 18 Haz 2019 |
56Planlayın | CVE-2021-22908İstismar yok | A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browseivanti · connect secure · CWE-120 | Yüksek8,8 | — | %69,4 | 27 May 2021 |
49Planlayın | CVE-2016-0799İstismar yok | The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, whiopenssl · openssl · CWE-119 | Kritik9,8 | — | %32,4 | 3 Mar 2016 |
48Planlayın | CVE-2016-0800Silahlaştırılmış | The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify meopenssl · openssl · CWE-200 | Orta5,9 | — | %82,1 | 1 Mar 2016 |
48Planlayın | CVE-2019-11542İstismar yok | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 anivanti · connect secure · CWE-787 | Yüksek7,2 | — | %65,6 | 25 Nis 2019 |
41Planlayın | CVE-2019-11540İstismar yok | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0Rivanti · connect secure | Kritik9,8 | — | %8,3 | 25 Nis 2019 |
41Planlayın | CVE-2016-4787İstismar yok | Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read senivanti · connect secure | Kritik10,0 | — | %2,5 | 26 May 2016 |
40Planlayın | CVE-2018-6320İstismar yok | A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pivanti · connect secure · CWE-20 | Kritik9,8 | — | %4,1 | 6 Eyl 2018 |
40Planlayın | CVE-2018-5299İstismar yok | A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policpulsesecure · pulse connect secure · CWE-787 | Kritik9,8 | — | %3,1 | 16 Oca 2018 |
40Planlayın | CVE-2020-8239İstismar yok | A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack.pulsesecure · pulse secure desktop client | Kritik9,8 | — | %2,0 | 28 Eki 2020 |
40Planlayın | CVE-2018-20810İstismar yok | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RXivanti · connect secure · CWE-326 | Kritik9,8 | — | %1,8 | 28 Haz 2019 |
39İzleyin | CVE-2018-18284İstismar yok | Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.artifex · ghostscript | Yüksek8,6 | — | %16,3 | 19 Eki 2018 |
37İzleyin | CVE-2019-11509İstismar yok | In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policyivanti · connect secure | Yüksek8,8 | — | %7,7 | 3 Haz 2019 |
36İzleyin | CVE-2020-8254Kavram kanıtı | A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a maliciopulsesecure · pulse secure desktop client · CWE-23 | Yüksek8,8 | — | %2,1 | 28 Eki 2020 |
36İzleyin | CVE-2020-11580İstismar yok | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.pulsesecure · pulse connect secure · CWE-295 | Kritik9,1 | — | %1,1 | 6 Nis 2020 |
35İzleyin | CVE-2022-21826İstismar yok | Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request,ivanti · connect secure · CWE-444 | Orta5,4 | — | %45,2 | 30 Eyl 2022 |
35İzleyin | CVE-2020-11581İstismar yok | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.pulsesecure · pulse connect secure · CWE-78 | Yüksek8,1 | — | %9,8 | 6 Nis 2020 |
35İzleyin | CVE-2016-4791İstismar yok | The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.ivanti · connect secure | Yüksek8,6 | — | %2,2 | 26 May 2016 |
35İzleyin | CVE-2017-11455İstismar yok | diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8,ivanti · connect secure · CWE-352 | Yüksek8,8 | — | %1,3 | 29 Ağu 2017 |
35İzleyin | CVE-2018-20193İstismar yok | Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) pulsesecure · secure access series ssl vpn sa-4000 · CWE-269 | Yüksek8,8 | — | %1,3 | 21 Ara 2018 |
35İzleyin | CVE-2020-11582İstismar yok | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.pulsesecure · pulse connect secure · CWE-668 | Yüksek8,8 | — | %0,9 | 6 Nis 2020 |
- CVE-2019-1153988Hemen
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %99ivanti · connect secure25 Nis 2019
- CVE-2020-821868Bu hafta
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code e
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %32ivanti · connect secure30 Tem 2020
- CVE-2021-2290062Bu hafta
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administra
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %14ivanti · connect secure27 May 2021
- CVE-2019-1147760Bu hafta
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
YüksekCVSS 7,5Kavram kanıtıEPSS %99linux · linux kernel18 Haz 2019
- CVE-2019-1147858Planlayın
SACK can cause extensive memory use via fragmented resend queue
YüksekCVSS 7,5İstismar yokEPSS %95linux · linux kernel18 Haz 2019
- CVE-2021-2290856Planlayın
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse
YüksekCVSS 8,8İstismar yokEPSS %69ivanti · connect secure27 May 2021
- CVE-2016-079949Planlayın
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, whi
KritikCVSS 9,8İstismar yokEPSS %32openssl · openssl3 Mar 2016
- CVE-2016-080048Planlayın
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify me
OrtaCVSS 5,9SilahlaştırılmışEPSS %82openssl · openssl1 Mar 2016
- CVE-2019-1154248Planlayın
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an
YüksekCVSS 7,2İstismar yokEPSS %66ivanti · connect secure25 Nis 2019
- CVE-2019-1154041Planlayın
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R
KritikCVSS 9,8İstismar yokEPSS %8ivanti · connect secure25 Nis 2019
- CVE-2016-478741Planlayın
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sen
KritikCVSS 10,0İstismar yokEPSS %2ivanti · connect secure26 May 2016
- CVE-2018-632040Planlayın
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and P
KritikCVSS 9,8İstismar yokEPSS %4ivanti · connect secure6 Eyl 2018
- CVE-2018-529940Planlayın
A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Polic
KritikCVSS 9,8İstismar yokEPSS %3pulsesecure · pulse connect secure16 Oca 2018
- CVE-2020-823940Planlayın
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack.
KritikCVSS 9,8İstismar yokEPSS %2pulsesecure · pulse secure desktop client28 Eki 2020
- CVE-2018-2081040Planlayın
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX
KritikCVSS 9,8İstismar yokEPSS %2ivanti · connect secure28 Haz 2019
- CVE-2018-1828439İzleyin
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
YüksekCVSS 8,6İstismar yokEPSS %16artifex · ghostscript19 Eki 2018
- CVE-2019-1150937İzleyin
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy
YüksekCVSS 8,8İstismar yokEPSS %8ivanti · connect secure3 Haz 2019
- CVE-2020-825436İzleyin
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicio
YüksekCVSS 8,8Kavram kanıtıEPSS %2pulsesecure · pulse secure desktop client28 Eki 2020
- CVE-2020-1158036İzleyin
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.
KritikCVSS 9,1İstismar yokEPSS %1pulsesecure · pulse connect secure6 Nis 2020
- CVE-2022-2182635İzleyin
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request,
OrtaCVSS 5,4İstismar yokEPSS %45ivanti · connect secure30 Eyl 2022
- CVE-2020-1158135İzleyin
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.
YüksekCVSS 8,1İstismar yokEPSS %10pulsesecure · pulse connect secure6 Nis 2020
- CVE-2016-479135İzleyin
The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.
YüksekCVSS 8,6İstismar yokEPSS %2ivanti · connect secure26 May 2016
- CVE-2017-1145535İzleyin
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8,
YüksekCVSS 8,8İstismar yokEPSS %1ivanti · connect secure29 Ağu 2017
- CVE-2018-2019335İzleyin
Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC)
YüksekCVSS 8,8İstismar yokEPSS %1pulsesecure · secure access series ssl vpn sa-400021 Ara 2018
- CVE-2020-1158235İzleyin
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06.
YüksekCVSS 8,8İstismar yokEPSS %1pulsesecure · pulse connect secure6 Nis 2020