Pulsesecure
pulsesecure
93 CVEs • 19 products
Products (19)
Click to collapseToggle
Products (19)
Click to collapse
CVEs (93)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureNov 21, 2024 Apr 6, 2020 N/A· v4 8.8 HIGH· v3 3.3 LOW· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server t...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureNov 21, 2024 Apr 6, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-mid...Show more |
1Pulsesecure 2Pulse Connect Secure Pulse Policy SecureNov 21, 2024 Apr 6, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SS...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Policy SecureNov 21, 2024 Jun 28, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX. |
1Pulsesecure 1Pulse Secure Desktop Client Nov 21, 2024 Jun 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Policy SecureNov 21, 2024 Jun 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not appl...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Policy SecureNov 21, 2024 Jun 28, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX. |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker c...Show more |
6Canonical F5Ivanti+3 more24Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+21 moreNov 21, 2024 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to caus...Show more |
2Ivanti Pulsesecure3Connect Secure Policy SecurePulse Policy SecureNov 21, 2024 Jun 3, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 bef...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureNov 21, 2024 May 8, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to exec...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Policy SecureNov 21, 2024 Apr 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Policy SecureNov 21, 2024 Apr 26, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureNov 21, 2024 Apr 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Policy SecureNov 21, 2024 Apr 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a...Show more |
2Ivanti Pulsesecure3Connect Secure Policy SecurePulse Policy SecureNov 6, 2025 Apr 26, 2019 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX...Show more |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Secure Desktop ClientNov 21, 2024 Apr 12, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573....Show more |
1Pulsesecure 1Secure Access Series Ssl Vpn Sa 4000 Nov 21, 2024 Dec 21, 2018 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1...Show more |
1Pulsesecure 1Virtual Traffic Manager Nov 21, 2024 Dec 20, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation. |
1Pulsesecure 1Virtual Traffic Manager Nov 21, 2024 Dec 20, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted webs...Show more |