Show filters
116 Total Results
Displaying 21-30 of 116
Sort by:
Attacker Value
Unknown
CVE-2020-8248
Disclosure Date: October 28, 2020 (last updated November 28, 2024)
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
0
Attacker Value
Unknown
CVE-2020-8240
Disclosure Date: October 28, 2020 (last updated November 28, 2024)
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.
0
Attacker Value
Unknown
CVE-2020-8255
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these messages.
0
Attacker Value
Unknown
CVE-2020-8263
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
0
Attacker Value
Unknown
CVE-2020-8249
Disclosure Date: October 28, 2020 (last updated February 22, 2025)
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
0
Attacker Value
Unknown
CVE-2020-8241
Disclosure Date: October 28, 2020 (last updated November 28, 2024)
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
0
Attacker Value
Unknown
CVE-2020-8956
Disclosure Date: October 27, 2020 (last updated February 22, 2025)
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.
0
Attacker Value
Unknown
CVE-2019-17091
Disclosure Date: October 02, 2019 (last updated November 27, 2024)
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
0
Attacker Value
Unknown
CVE-2018-20812
Disclosure Date: June 28, 2019 (last updated November 27, 2024)
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.
0
Attacker Value
Unknown
CVE-2019-0227
Disclosure Date: May 01, 2019 (last updated November 08, 2023)
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
0