CVE-2020-8263
- EPSS 0.35%
- Veröffentlicht 28.10.2020 13:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:36
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
CVE-2020-8239
- EPSS 0.39%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:34
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.
CVE-2020-8255
- EPSS 15.05%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:36
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.
CVE-2020-8254
- EPSS 2.44%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:35
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To improve the security of connections between Pulse cl...
CVE-2020-8250
- EPSS 0.35%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:35
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
CVE-2020-8249
- EPSS 0.65%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:35
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
CVE-2020-8248
- EPSS 0.41%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:35
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
CVE-2020-8241
- EPSS 3.5%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:34
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
CVE-2020-8240
- EPSS 0.04%
- Veröffentlicht 28.10.2020 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:34
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if ...
CVE-2020-15408
- EPSS 0.33%
- Veröffentlicht 28.07.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 05:05:29
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.