Show filters
137 Total Results
Displaying 101-110 of 137
Sort by:
Attacker Value
Unknown
CVE-2017-11195
Disclosure Date: July 12, 2017 (last updated November 26, 2024)
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.
0
Attacker Value
Unknown
CVE-2016-2408
Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4786
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4789
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4790
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4791
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-4788
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-4787
Disclosure Date: May 26, 2016 (last updated February 28, 2024)
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-3985
Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-7323
Disclosure Date: October 05, 2015 (last updated October 05, 2023)
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetings by leveraging a meeting id and meetingAppSun.jar.
0