Vulnerabilities > Juniper

DATE CVE VULNERABILITY TITLE RISK
2006-07-13 CVE-2006-3567 HTML Injection vulnerability in Juniper DX 5.1
Cross-site scripting (XSS) vulnerability in the web administration interface logging feature in Juniper Networks (Redline) DX 5.1.x, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the username login field.
network
juniper
4.3
2006-07-12 CVE-2006-3529 Remote Denial of Service vulnerability in Juniper Networks JUNOS IPv6 Packet Processing
Memory leak in Juniper JUNOS 6.4 through 8.0, built before May 10, 2006, allows remote attackers to cause a denial of service (kernel packet memory consumption and crash) via crafted IPv6 packets whose buffers are not released after they are processed.
network
low complexity
juniper
5.0
2006-04-29 CVE-2006-2086 Remote Buffer Overflow vulnerability in Juniper SSL-VPN Client ActiveX Control
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, allows remote attackers to execute arbitrary code via a long argument in the ProductName parameter.
network
low complexity
juniper
7.5
2006-04-27 CVE-2006-2074 Denial Of Service vulnerability in Juniper JUNOSe DNS Client
Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS "client code," as demonstrated by the OUSPG PROTOS DNS test suite.
network
low complexity
juniper
critical
10.0
2005-12-30 CVE-2005-4587 Remote Denial of Service vulnerability in Juniper NetScreen-Security Manager 2004
Juniper NetScreen-Security Manager (NSM) 2004 FP2 and FP3 allow remote attackers to cause a denial of service (crash or hang of server components that are automatically restarted) via a long crafted string on (1) port 7800 (the GUI Server port) or (2) port 7801 (the Device Server port).
network
low complexity
juniper
7.8
2005-11-21 CVE-2005-3733 Multiple Unspecified vulnerability in Juniper Networks Routers ISAKMP IKE Traffic
The Internet Key Exchange version 1 (IKEv1) implementation in Juniper JUNOS and JUNOSe software for M, T, and J-series routers before release 6.4, and E-series routers before 7-1-0, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
juniper
7.5
2005-08-23 CVE-2005-2640 Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
network
low complexity
neoteris juniper netscreen
5.0
2004-12-31 CVE-2004-1446 Denial Of Service vulnerability in Juniper Networks NetScreen SSHv1
Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.
network
low complexity
juniper
5.0
2004-12-31 CVE-2004-0467 Remote Denial Of Service vulnerability in Juniper Networks JUNOS
Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other packets are processed.
network
low complexity
juniper
5.0
2004-12-06 CVE-2004-0468 Unspecified vulnerability in Juniper Junos
Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.
network
low complexity
juniper
5.0