imPC@ndo EN

Vulnerabilità Juniper

1105 CVE

CVE-2015-3209
Alta 7.5

Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.

arista eos · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 14
0.10EPSS
CVE-2013-4685
Alta 10.0

Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code v…

juniper junos · juniper srx100 · juniper srx110 · juniper srx1400 · e altri 9
0.08EPSS
CVE-2014-0429
Alta 10.0

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

canonical ubuntu_linux · debian debian_linux · ibm forms_viewer · juniper junos_space · e altri 3
0.08EPSS
CVE-2008-2476
Alta 9.3

The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neigh…

force10 ftos · freebsd freebsd · juniper jnos · netbsd netbsd · e altri 2
0.07EPSS
CVE-2014-0457
Alta 10.0

Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

canonical ubuntu_linux · debian debian_linux · ibm forms_viewer · juniper junos_space · e altri 3
0.07EPSS
CVE-2005-2640
Media 5.0

Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a re…

juniper netscreen-5gt · juniper netscreen-idp · juniper netscreen-idp_10 · juniper netscreen-idp_100 · e altri 12
0.07EPSS
CVE-2014-2421
Alta 10.0

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

canonical ubuntu_linux · debian debian_linux · ibm forms_viewer · juniper junos_space · e altri 3
0.07EPSS
CVE-2014-0456
Alta 10.0

Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

canonical ubuntu_linux · debian debian_linux · ibm forms_viewer · juniper junos_space · e altri 3
0.07EPSS
CVE-2018-0001
Critica 9.8

A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the context of the J-Web process. Affected releases are Juniper N…

juniper junos
0.06EPSS
CVE-2020-7656
Media 6.1

jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.…

jquery jquery · juniper junos · netapp active_iq_unified_manager · netapp cloud_backup · e altri 3
0.06EPSS
CVE-2014-6500
Alta 7.5

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris
0.06EPSS
CVE-2014-6491
Alta 7.5

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris
0.06EPSS
CVE-2017-10622
Critica 9.8

An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote unauthenticated network based attacker to login as any privileged user. This issue only affects Junos Space Network Management Platform 17.1R1…

juniper junos_space
0.05EPSS
CVE-2005-3733
Alta 7.5

The Internet Key Exchange version 1 (IKEv1) implementation in Juniper JUNOS and JUNOSe software for M, T, and J-series routers before release 6.4, and E-series routers before 7-1-0, allows remote attackers to cause a denial of service and possibly execute arbi…

juniper junos_e · juniper junos_j · juniper junos_m · juniper junos_t · e altri 4
0.05EPSS
CVE-2019-0006
Critica 9.8

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series devices in a Virtual Chassis configuration. This issue can result in a crash of the …

juniper junos
0.05EPSS
CVE-2014-0453
Media 4.0

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.

canonical ubuntu_linux · debian debian_linux · ibm forms_viewer · juniper junos_space · e altri 3
0.05EPSS
CVE-2018-0052
Alta 7.2

If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the device. RSH service is disabled by default on Junos. There is no documented CLI command to enable this service. How…

juniper junos
0.05EPSS
CVE-2014-6494
Media 4.3

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris · e altri 4
0.05EPSS
CVE-2015-2620
Media 4.3

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.

canonical ubuntu_linux · debian debian_linux · juniper junos_space · mariadb mariadb · e altri 2
0.05EPSS
CVE-2014-3412
Alta 10.0

Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors.

juniper junos_space · juniper junos_space_ja1500_appliance · juniper junos_space_ja2500_appliance
0.05EPSS
CVE-2014-6559
Media 4.3

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris · e altri 4
0.05EPSS
CVE-2019-0008
Critica 9.8

A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet Forwarding Engine manager (FXPC) process on QFX5000 series, EX4300, EX4600 devices. This issue can result in a crash of the fxpc daemon or may …

juniper junos
0.05EPSS
CVE-2014-0460
Media 5.8

Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.

canonical ubuntu_linux · debian debian_linux · juniper junos_space · oracle jdk · e altri 2
0.04EPSS
CVE-2014-6496
Media 4.3

Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris · e altri 4
0.04EPSS
CVE-2006-3529
Media 5.0

Memory leak in Juniper JUNOS 6.4 through 8.0, built before May 10, 2006, allows remote attackers to cause a denial of service (kernel packet memory consumption and crash) via crafted IPv6 packets whose buffers are not released after they are processed.

juniper junos
0.04EPSS