Vulnerabilities > Paloaltonetworks > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-08-23 CVE-2019-1580 Out-of-bounds Write vulnerability in Paloaltonetworks Pan-Os
Memory corruption in PAN-OS 7.1.24 and earlier, PAN-OS 8.0.19 and earlier, PAN-OS 8.1.9 and earlier, and PAN-OS 9.0.3 and earlier will allow a remote, unauthenticated user to craft a message to Secure Shell Daemon (SSHD) and corrupt arbitrary memory.
network
low complexity
paloaltonetworks CWE-787
critical
10.0
2018-12-12 CVE-2018-10143 Improper Privilege Management vulnerability in Paloaltonetworks Expedition 1.0.107
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.
network
low complexity
paloaltonetworks CWE-269
critical
10.0
2017-12-11 CVE-2017-15944 Unspecified vulnerability in Paloaltonetworks Pan-Os
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
network
low complexity
paloaltonetworks
critical
9.8
2017-12-11 CVE-2017-15940 Command Injection vulnerability in Paloaltonetworks Pan-Os
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
network
low complexity
paloaltonetworks CWE-77
critical
9.0
2017-08-02 CVE-2017-8390 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via a crafted domain name.
network
low complexity
paloaltonetworks CWE-20
critical
10.0
2017-06-01 CVE-2015-6531 Code Injection vulnerability in Paloaltonetworks Pan-Os
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
network
paloaltonetworks CWE-94
critical
9.3
2016-11-19 CVE-2016-9150 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Paloaltonetworks Pan-Os
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
paloaltonetworks CWE-119
critical
10.0
2016-04-12 CVE-2016-3657 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Paloaltonetworks Pan-Os
Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to cause a denial of service (device crash) or possibly execute arbitrary code via an SSL VPN request.
network
low complexity
paloaltonetworks CWE-119
critical
10.0
2016-04-12 CVE-2016-3655 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.
network
low complexity
paloaltonetworks CWE-20
critical
10.0
2016-04-12 CVE-2016-3654 Improper Input Validation vulnerability in Paloaltonetworks Pan-Os
The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.
network
low complexity
paloaltonetworks CWE-20
critical
9.0