Palo Alto Networks / Pan-OS
235 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2016-9151 | Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows loca… | HIGH | 7.8 | Nov 19, 2016 |
| CVE-2016-9150 | Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.… | CRITICAL | 9.8 | Nov 19, 2016 |
| CVE-2016-9149 | The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and… | MEDIUM | 6.5 | Nov 19, 2016 |
| CVE-2016-5195 KEV | kernel: mm: privilege escalation via MAP_PRIVATE COW breakage | HIGH | 7.0 | Nov 10, 2016 |
| CVE-2016-1712 | Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain… | HIGH | 7.8 | Aug 2, 2016 |
| CVE-2016-2219 | Cross-site scripting (XSS) vulnerability in the management interface in Palo Alto Networks PAN-OS 7.x before 7.0.8 allows remote authenticated users to inject… | MEDIUM | 5.4 | Jul 12, 2016 |
| CVE-2016-4971 | wget: Lack of filename checking allows arbitrary file upload via FTP redirect | HIGH | 8.8 | Jun 30, 2016 |
| CVE-2016-3657 | Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows… | CRITICAL | 9.8 | Apr 12, 2016 |
| CVE-2016-3656 | The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers… | HIGH | 7.5 | Apr 12, 2016 |
| CVE-2016-3655 | The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attacke… | CRITICAL | 9.8 | Apr 12, 2016 |
| CVE-2016-3654 | The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, a… | HIGH | 7.2 | Apr 12, 2016 |
| CVE-2015-4162 | XML external entity (XXE) vulnerability in the management interface in PAN-OS before 5.0.16, 6.x before 6.0.8, and 6.1.x before 6.1.4 allows remote authenticat… | MEDIUM | 4.0 | Jun 2, 2015 |
| CVE-2014-3764 | Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.… | MEDIUM | 4.3 | Jan 6, 2015 |
| CVE-2013-5664 | Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allow… | MEDIUM | 4.3 | Aug 31, 2013 |
| CVE-2013-5663 | The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended sec… | MEDIUM | 4.3 | Aug 31, 2013 |
| CVE-2012-6605 | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arb… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6604 | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arb… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6603 | The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication… | HIGH | 10.0 | Aug 31, 2013 |
| CVE-2012-6602 | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arb… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6601 | The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to… | HIGH | 10.0 | Aug 31, 2013 |
| CVE-2012-6600 | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execut… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6599 | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execut… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6598 | The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands vi… | HIGH | 9.0 | Aug 31, 2013 |
| CVE-2012-6597 | Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by usin… | MEDIUM | 6.3 | Aug 31, 2013 |
| CVE-2012-6596 | Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers… | MEDIUM | 5.0 | Aug 31, 2013 |
Showing 226 to 235 of 235 CVEs