CVE-2020-1987
- EPSS 0.11%
- Veröffentlicht 08.04.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:47
An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Pal...
CVE-2020-1976
- EPSS 0.13%
- Veröffentlicht 12.02.2020 23:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:46
A denial-of-service (DoS) vulnerability in Palo Alto Networks GlobalProtect software running on Mac OS allows authenticated local users to cause the Mac OS kernel to hang or crash. This issue affects GlobalProtect 5.0.5 and earlier versions of Global...
CVE-2019-17436
- EPSS 0.04%
- Veröffentlicht 16.10.2019 19:15:16
- Zuletzt bearbeitet 21.11.2024 04:32:19
A Local Privilege Escalation vulnerability exists in GlobalProtect Agent for Linux and Mac OS X version 5.0.4 and earlier and version 4.1.12 and earlier, that can allow non-root users to overwrite root files on the file system.
CVE-2019-17435
- EPSS 0.04%
- Veröffentlicht 16.10.2019 19:15:16
- Zuletzt bearbeitet 21.11.2024 04:32:19
A Local Privilege Escalation vulnerability exists in the GlobalProtect Agent for Windows 5.0.3 and earlier, and GlobalProtect Agent for Windows 4.1.12 and earlier, in which the auto-update feature can allow for modification of a GlobalProtect Agent M...
CVE-2019-1573
- EPSS 0.39%
- Veröffentlicht 09.04.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:36:50
GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or ses...
CVE-2017-15870
- EPSS 0.09%
- Veröffentlicht 11.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."
CVE-2012-6606
- EPSS 0.23%
- Veröffentlicht 31.08.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.