Vulnerabilities > Pulsesecure

DATE CVE VULNERABILITY TITLE RISK
2016-04-12 CVE-2016-3985 Improper Access Control vulnerability in Pulsesecure Pulse Connect Secure 8.1R7/8.2R1
The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.
network
low complexity
pulsesecure CWE-284
6.5
2016-03-03 CVE-2016-0799 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.
network
low complexity
openssl pulsesecure CWE-119
critical
9.8
2016-03-01 CVE-2016-0800 Information Exposure vulnerability in multiple products
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
network
high complexity
openssl pulsesecure CWE-200
5.9