Vulnerabilities > Paloaltonetworks > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-12 CVE-2020-1976 Improper Input Validation vulnerability in Paloaltonetworks Globalprotect
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash.
local
low complexity
paloaltonetworks CWE-20
5.5
2019-10-16 CVE-2019-17435 Unspecified vulnerability in Paloaltonetworks Globalprotect
A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent MSI installer package on disk before installation.
local
low complexity
paloaltonetworks
5.5
2019-07-01 CVE-2019-1578 Cross-site Scripting vulnerability in Paloaltonetworks Minemeld 0.9.60
Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker able to convince an authenticated MineMeld admin to type malicious input in the MineMeld UI could execute arbitrary JavaScript code in the admin’s browser.
network
low complexity
paloaltonetworks CWE-79
6.1
2019-07-01 CVE-2019-1577 Code Injection vulnerability in Paloaltonetworks Traps 5.0/5.0.5
Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.
network
low complexity
paloaltonetworks CWE-94
6.3
2019-05-09 CVE-2019-1568 Cross-site Scripting vulnerability in Paloaltonetworks Demisto 4.5
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML.
network
low complexity
paloaltonetworks CWE-79
6.1
2019-04-12 CVE-2019-1574 Cross-site Scripting vulnerability in Paloaltonetworks Expedition Migration Tool
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
network
low complexity
paloaltonetworks CWE-79
5.4
2019-04-09 CVE-2019-1567 Cross-site Scripting vulnerability in Paloaltonetworks Expedition Migration Tool
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
network
low complexity
paloaltonetworks CWE-79
5.4
2019-03-26 CVE-2019-1571 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
network
low complexity
paloaltonetworks CWE-79
4.8
2019-03-26 CVE-2019-1570 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
network
low complexity
paloaltonetworks CWE-79
4.8
2019-03-26 CVE-2019-1569 Cross-site Scripting vulnerability in Paloaltonetworks Expedition
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
network
low complexity
paloaltonetworks CWE-79
4.8