Vulnerabilities > Paloaltonetworks > PAN OS > 9.1.0

DATE CVE VULNERABILITY TITLE RISK
2020-05-13 CVE-2020-2015 Classic Buffer Overflow vulnerability in Paloaltonetworks Pan-Os
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges.
network
low complexity
paloaltonetworks CWE-120
8.8
2020-05-13 CVE-2020-2013 Cleartext Transmission of Sensitive Information vulnerability in Paloaltonetworks Pan-Os
A cleartext transmission of sensitive information vulnerability in Palo Alto Networks PAN-OS Panorama that discloses an authenticated PAN-OS administrator's PAN-OS session cookie.
network
low complexity
paloaltonetworks CWE-319
8.8
2020-05-13 CVE-2020-2003 Unspecified vulnerability in Paloaltonetworks Pan-Os
An external control of filename vulnerability in the command processing of PAN-OS allows an authenticated administrator to delete arbitrary system files affecting the integrity of the system or causing denial of service to all PAN-OS services.
network
low complexity
paloaltonetworks
6.5
2020-05-13 CVE-2020-1998 Incorrect Authorization vulnerability in Paloaltonetworks Pan-Os
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication.
network
low complexity
paloaltonetworks CWE-863
8.8
2020-05-13 CVE-2020-1995 NULL Pointer Dereference vulnerability in Paloaltonetworks Pan-Os 9.1.0/9.1.1
A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash.
network
low complexity
paloaltonetworks CWE-476
4.9
2020-04-08 CVE-2020-1992 Use of Externally-Controlled Format String vulnerability in Paloaltonetworks Pan-Os
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially execute code with root privileges.
network
low complexity
paloaltonetworks CWE-134
critical
9.8