Vulnerabilities > Parallels

DATE CVE VULNERABILITY TITLE RISK
2020-08-25 CVE-2020-17390 Out-of-bounds Read vulnerability in Parallels Desktop
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
local
low complexity
parallels CWE-125
8.8
2020-07-24 CVE-2020-15860 Unspecified vulnerability in Parallels Remote Application Server 17.1.1
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution.
network
low complexity
parallels
critical
9.9
2020-03-23 CVE-2020-8876 Out-of-bounds Read vulnerability in Parallels Desktop
This vulnerability allows local attackers to disclose information on affected installations of Parallels Desktop 15.1.2-47123.
local
low complexity
parallels CWE-125
5.5
2020-03-23 CVE-2020-8875 Out-of-bounds Write vulnerability in Parallels Desktop
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
local
low complexity
parallels CWE-787
8.8
2020-03-23 CVE-2020-8874 Integer Overflow or Wraparound vulnerability in Parallels Desktop
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
local
low complexity
parallels CWE-190
6.7
2020-03-23 CVE-2020-8873 Improper Privilege Management vulnerability in Parallels Desktop
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.2-47123.
local
low complexity
parallels CWE-269
6.7
2020-03-23 CVE-2020-8872 Out-of-bounds Read vulnerability in Parallels Desktop
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.1-47117.
local
low complexity
parallels CWE-125
4.4
2020-03-23 CVE-2020-8871 Out-of-bounds Write vulnerability in Parallels Desktop
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.0-47107 .
local
low complexity
parallels CWE-787
6.7
2020-01-21 CVE-2020-7213 Cleartext Storage of Sensitive Information vulnerability in Parallels 13
Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks.
network
high complexity
parallels CWE-312
7.5
2020-01-07 CVE-2019-17148 OS Command Injection vulnerability in Parallels Desktop 14.1.3
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485).
local
low complexity
parallels CWE-78
7.8