|
199231
|
6.5 |
MEDIUM
Local
|
katacontainers
|
runtime
|
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on th…
|
CWE-59
Link Following
|
CVE-2020-2024
|
2024-11-21 14:24 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199232
|
9.0 |
CRITICAL
Network
|
paloaltonetworks
|
pan-os
|
An authentication bypass vulnerability in the Panorama context switching feature allows an attacker with network access to a Panorama's management interface to gain privileged access to managed firew…
|
CWE-287
Improper Authentication
|
CVE-2020-2018
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199233
|
6.1 |
MEDIUM
Network
|
paloaltonetworks
|
pan-os
|
A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to…
|
CWE-79
Cross-site Scripting
|
CVE-2020-2017
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199234
|
7.0 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker wh…
|
CWE-362
Race Condition
|
CVE-2020-2016
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199235
|
8.8 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
A buffer overflow vulnerability in the PAN-OS management server allows authenticated users to crash system processes or potentially execute arbitrary code with root privileges. This issue affects: PA…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-2015
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199236
|
8.8 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of P…
|
CWE-78
OS Command
|
CVE-2020-2014
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199237
|
7.5 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthenticated attackers with network access to the Panora…
|
CWE-611
XXE
|
CVE-2020-2012
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199238
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of P…
|
CWE-78
OS Command
|
CVE-2020-2010
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199239
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An external control of filename vulnerability in the SD WAN component of Palo Alto Networks PAN-OS Panorama allows an authenticated administrator to send a request that results in the creation and wr…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-2009
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199240
|
7.2 |
HIGH
Network
|
paloaltonetworks
|
pan-os
|
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system…
|
CWE-78
OS Command
|
CVE-2020-2008
|
2024-11-21 14:24 |
2020-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|