CVE-2020-8220
- EPSS 6.67%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:31
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
CVE-2020-12880
- EPSS 0.08%
- Published 27.07.2020 23:15:12
- Last modified 21.11.2024 05:00:28
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the en...
CVE-2018-20809
- EPSS 3.31%
- Published 28.06.2019 18:15:11
- Last modified 21.11.2024 04:02:13
A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.
CVE-2018-20810
- EPSS 1.54%
- Published 28.06.2019 18:15:11
- Last modified 21.11.2024 04:02:13
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX...
CVE-2018-20811
- EPSS 0.71%
- Published 28.06.2019 18:15:11
- Last modified 21.11.2024 04:02:13
A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.
CVE-2018-20813
- EPSS 3.85%
- Published 28.06.2019 18:15:11
- Last modified 21.11.2024 04:02:14
An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.
CVE-2018-20814
- EPSS 0.11%
- Published 28.06.2019 18:15:11
- Last modified 21.11.2024 04:02:14
An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.
CVE-2018-20807
- EPSS 0.12%
- Published 28.06.2019 18:15:10
- Last modified 21.11.2024 04:02:13
An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.
CVE-2018-20808
- EPSS 0.12%
- Published 28.06.2019 18:15:10
- Last modified 21.11.2024 04:02:13
An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.
CVE-2019-11477
- EPSS 71.15%
- Published 19.06.2019 00:15:12
- Last modified 21.11.2024 04:21:09
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This ha...