Vulnerabilities > Pulsesecure
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-05-27 | CVE-2021-22894 | Classic Buffer Overflow vulnerability in Pulsesecure Pulse Connect Secure A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. | 9.0 |
2021-05-27 | CVE-2021-22899 | Command Injection vulnerability in Pulsesecure Pulse Connect Secure A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature | 6.5 |
2021-05-27 | CVE-2021-22900 | Incorrect Resource Transfer Between Spheres vulnerability in Pulsesecure Pulse Connect Secure A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. | 6.5 |
2021-05-27 | CVE-2021-22908 | Classic Buffer Overflow vulnerability in Pulsesecure Pulse Connect Secure 9.0/9.0Rx/9.1 A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. | 9.0 |
2021-05-14 | CVE-2021-31922 | HTTP Request Smuggling vulnerability in Pulsesecure Virtual Traffic Manager An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. | 5.0 |
2021-04-23 | CVE-2021-22893 | Use After Free vulnerability in Pulsesecure Pulse Connect Secure 9.0/9.1 Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. | 10.0 |
2021-03-16 | CVE-2021-22887 | A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. | 2.1 |
2020-10-28 | CVE-2020-8263 | Cross-site Scripting vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1 A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file. | 3.5 |
2020-10-28 | CVE-2020-8262 | Cross-site Scripting vulnerability in Pulsesecure Pulse Connect Secure 7.1/7.4 A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface. | 4.3 |
2020-10-28 | CVE-2020-8261 | Classic Buffer Overflow vulnerability in Pulsesecure Pulse Connect Secure 7.1/7.4 A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection. | 4.3 |