Show filters
214 Total Results
Displaying 161-170 of 214
Sort by:
Attacker Value
Unknown
CVE-2018-7636
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.
0
Attacker Value
Unknown
CVE-2017-16878
Disclosure Date: January 10, 2018 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.
0
Attacker Value
Unknown
CVE-2017-17841
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect portal or gateway, might allow remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a ROBOT attack.
0
Attacker Value
Unknown
CVE-2017-15941
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7, when the GlobalProtect gateway or portal is configured, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-16878
Disclosure Date: January 10, 2018 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject arbitrary web script or HTML by leveraging an unspecified configuration.
0
Attacker Value
Unknown
CVE-2017-15942
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.
0
Attacker Value
Unknown
CVE-2017-15940
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-15943
Disclosure Date: December 11, 2017 (last updated November 26, 2024)
The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.
0
Attacker Value
Unknown
CVE-2017-15944
Disclosure Date: December 11, 2017 (last updated June 29, 2024)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.
0
Attacker Value
Unknown
CVE-2016-8610
Disclosure Date: November 13, 2017 (last updated January 27, 2024)
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
0