Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Pan Os MEDIUM 5.4
CVE-2019-1565

The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier, may allow an attacker that …

Fix: after 8.1.5
Fix from $1,600 2019-01-30
Expedition CRITICAL 9.8
CVE-2018-10143EPSS 25%

The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…

No fix yet
Fix from $2,300 2018-12-12
Expedition HIGH 7.5
CVE-2018-10142

The Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.

Mitigation only
Fix from $1,950 2018-11-27
Pan Os MEDIUM 6.1
CVE-2018-10141

GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.

Fix: 6.1.0 / 8.1.4+
Fix from $1,600 2018-10-12
Pan Os HIGH 7.8
CVE-2018-14634 KEVEPSS 15%

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise p…

Fix: 7.1.23 / 8.0.16+
Fix from $1,950 2018-09-25
Pan Os MEDIUM 6.1
CVE-2018-10139

The PAN-OS response for GlobalProtect Gateway in Palo Alto Networks PAN-OS 6.1.21 and earlier, PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier m…

Fix: after 8.0.11
Fix from $1,600 2018-08-16
Pan Os MEDIUM 5.4
CVE-2018-9337

The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and…

Fix: after 8.1.1
Fix from $1,600 2018-07-03
Pan Os MEDIUM 6.1
CVE-2018-7636

The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially craf…

Mitigation only
Fix from $1,600 2018-07-03
Pan Os MEDIUM 5.5
CVE-2018-9242

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to d…

Fix: after 8.0.9
Fix from $1,600 2018-07-03
Pan Os MEDIUM 5.5
CVE-2018-9334

The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allo…

Fix: after 8.0.8
Fix from $1,600 2018-07-03
Pan Os MEDIUM 5.4
CVE-2018-9335

The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow …

Fix: after 8.1.1
Fix from $1,600 2018-07-03
Pan Os MEDIUM 6.1
CVE-2017-15941

Cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.7…

Fix: 6.1.19 / 7.0.19+
Fix from $1,600 2018-01-10
Pan Os MEDIUM 6.1
CVE-2017-16878

Cross-site scripting (XSS) vulnerability in the Captive Portal function in Palo Alto Networks PAN-OS before 8.0.7 allows remote attackers to inject a…

Fix: 8.0.7+
Fix from $1,600 2018-01-10
Pan Os MEDIUM 5.9
CVE-2017-17841

Palo Alto Networks PAN-OS 6.1, 7.1, and 8.0.x before 8.0.7, when an interface implements SSL decryption with RSA enabled or hosts a GlobalProtect por…

Mitigation only
Fix from $1,600 2018-01-10
Pan Os CRITICAL 9.8
CVE-2017-15940

The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x…

Fix: 6.1.19 / 7.0.19+
Fix from $2,300 2017-12-11
Pan Os CRITICAL 9.8
CVE-2017-15944 KEVEPSS 98%

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrar…

Fix: 6.1.19 / 7.0.19+
Fix from $2,300 2017-12-11
Pan Os HIGH 7.5
CVE-2017-15942

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial o…

Fix: 6.1.19 / 7.0.19+
Fix from $1,950 2017-12-11
Globalprotect MEDIUM 6.7
CVE-2017-15870

Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via ve…

Fix: after 4.0.2
Fix from $1,600 2017-12-11
Pan Os MEDIUM 5.3
CVE-2017-15943

The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS bef…

Fix: 6.1.19 / 7.0.19+
Fix from $1,600 2017-12-11
Pan Os CRITICAL 9.8
CVE-2017-9458

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.…

Fix: after 6.1.17
Fix from $2,300 2017-09-07
Pan Os MEDIUM 6.1
CVE-2017-12416

Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0…

Fix: after 6.1.17
Fix from $1,600 2017-09-07
Pan Os MEDIUM 6.1
CVE-2017-9459

Cross-site scripting (XSS) vulnerability in the management web interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before …

Fix: after 6.1.17
Fix from $1,600 2017-08-02
Pan Os MEDIUM 6.1
CVE-2017-9467

Cross-site scripting (XSS) vulnerability in the GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x…

Fix: after 6.1.17
Fix from $1,600 2017-08-02
Pan Os CRITICAL 9.8
CVE-2017-8390EPSS 6%

The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to exe…

Fix: after 6.1.17
Fix from $2,300 2017-08-02
Pan Os HIGH 7.8
CVE-2015-6531

Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmwar…

Fix: after 6.0
Fix from $1,950 2017-06-01
Pan Os MEDIUM 6.5
CVE-2017-7216

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to obtain sensitive information via unspecif…

Fix: after 7.1.8
Fix from $1,600 2017-05-02
Pan Os CRITICAL 9.8
CVE-2017-7945

The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides…

Fix: after 6.1.15
Fix from $2,300 2017-04-29
Pan Os MEDIUM 6.5
CVE-2017-7644

The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users …

Fix: after 6.1.15
Fix from $1,600 2017-04-29
Pan Os MEDIUM 6.1
CVE-2017-7409

Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-…

Fix: after 7.0.14
Fix from $1,600 2017-04-21
Pan Os HIGH 7.8
CVE-2017-7218

The Management Web Interface in Palo Alto Networks PAN-OS before 7.1.9 allows remote authenticated users to gain privileges via unspecified request p…

Fix: after 7.1.8
Fix from $1,950 2017-04-14