Vulnerabilities > Pulsesecure

DATE CVE VULNERABILITY TITLE RISK
2018-11-29 CVE-2018-11002 Incorrect Permission Assignment for Critical Resource vulnerability in Pulsesecure Pulse Secure Desktop Client
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.
local
low complexity
pulsesecure CWE-732
5.5
2018-10-19 CVE-2018-18284 Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
local
low complexity
artifex debian canonical redhat pulsesecure
8.6
2018-09-12 CVE-2018-7572 Improper Authentication vulnerability in Pulsesecure Pulse Secure Desktop
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client.
low complexity
pulsesecure CWE-287
6.8
2018-09-06 CVE-2018-6320 Improper Input Validation vulnerability in multiple products
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
network
low complexity
pulsesecure ivanti CWE-20
critical
9.8
2018-09-06 CVE-2018-16261 Improper Certificate Validation vulnerability in Pulsesecure Pulse Secure Desktop Client
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
low complexity
pulsesecure CWE-295
6.8
2018-09-06 CVE-2018-15865 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
local
low complexity
pulsesecure
7.8
2018-09-06 CVE-2018-15749 Use of Externally-Controlled Format String vulnerability in Pulsesecure Pulse Secure Desktop Client
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
local
low complexity
pulsesecure CWE-134
5.5
2018-09-06 CVE-2018-15726 OS Command Injection vulnerability in Pulsesecure Pulse Secure Desktop Client
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
local
low complexity
pulsesecure CWE-78
5.3
2018-09-06 CVE-2018-14366 Open Redirect vulnerability in multiple products
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
network
low complexity
pulsesecure ivanti CWE-601
6.1
2018-09-05 CVE-2018-16513 Incorrect Type Conversion or Cast vulnerability in multiple products
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
local
low complexity
artifex debian canonical pulsesecure CWE-704
7.8