Skip to main content

Vendor/product archive

parallels / remote_application_server CVEs

Beta · best-effort

7 CVEs tagged to parallels / remote_application_server2 Critical, 4 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2023-45894

Published Dec 14, 2023

The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code e…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-40870

Published Nov 23, 2022

The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8968

Published Dec 17, 2021

Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Paral…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35710

Published Dec 25, 2020

Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15860

Published Jul 24, 2020

Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backen…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-9447

Published Feb 28, 2018

In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1