Skip to main content

Vendor archive

paloaltonetworks CVEs

Beta · best-effort

369 CVEs tagged to vendor paloaltonetworks40 Critical, 127 High, 178 Medium, 24 Low, 0 Unrated.

CVE-2017-7216

Published May 2, 2017

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecified request parameters.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7945

Published Apr 29, 2017

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7644

Published Apr 29, 2017

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive informatio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7409

Published Apr 21, 2017

Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7408

Published Apr 14, 2017

Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7218

Published Apr 14, 2017

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request parameters.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7217

Published Apr 14, 2017

The Management Web Interface in Palo Alto Networks PAN-OS before 7.0.14 and 7.1.x before 7.1.9 allows remote attackers to write to export files via unspecified parameters.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6356

Published Mar 20, 2017

Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive sess…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5584

Published Mar 15, 2017

Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows re…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5583

Published Mar 15, 2017

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9151

Published Nov 19, 2016

Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain priv…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9150

Published Nov 19, 2016

Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9149

Published Nov 19, 2016

The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1712

Published Aug 2, 2016

Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by levera…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2219

Published Jul 12, 2016

Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject arbitrary web script…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3657

Published Apr 12, 2016

Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3656

Published Apr 12, 2016

The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3655

Published Apr 12, 2016

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitr…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3654

Published Apr 12, 2016

The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4162

Published Jun 2, 2015

XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticated administrators to…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3764

Published Jan 6, 2015

Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 369 CVEsPage 14 of 15