Vulnerabilities > Juniper

DATE CVE VULNERABILITY TITLE RISK
2004-08-18 CVE-2004-0230 TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
network
low complexity
oracle openpgp mcafee netbsd xinuos juniper
5.0
2004-01-20 CVE-2004-1766 Remote Communication vulnerability in NetScreen Security Manager Insecure Default
The default installation of NetScreen-Security Manager before Feature Pack 1 does not enable encryption for communication with devices running ScreenOS 5.0, which allows remote attackers to obtain sensitive information via sniffing.
network
low complexity
juniper
5.0
2003-03-31 CVE-2002-1547 Unspecified vulnerability in Juniper Netscreen Screenos
Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CVE-2001-0144.
network
low complexity
juniper
5.0
2002-12-31 CVE-2002-2223 Unspecified vulnerability in Juniper products
Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) large number of payloads, or (3) a long payload.
network
high complexity
juniper
5.1
2002-12-31 CVE-2002-2150 Unspecified vulnerability in Juniper Netscreen Screenos
Firewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet flooding attacks such as (1) TCP SYN flood, (2) UDP flood, or (3) Crikey CRC Flood, which causes the firewall to refuse any new connections.
network
low complexity
juniper
5.0
2002-10-04 CVE-2002-0891 Remote Reboot vulnerability in NetScreen ScreenOS
The web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause a denial of service (crash) via a long user name.
network
low complexity
juniper
5.0
2002-05-29 CVE-2002-0234 Unspecified vulnerability in Juniper Netscreen Screenos
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.
local
low complexity
juniper
2.1
2001-08-22 CVE-2001-0589 Unspecified vulnerability in Juniper Netscreen Screenos
NetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific traffic patterns.
local
low complexity
juniper
2.1