Vulnerabilities > Juniper > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-09-13 CVE-2013-5649 Cross-Site Scripting vulnerability in Juniper IVE OS
Multiple cross-site scripting (XSS) vulnerabilities in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.1 before 7.1r15, 7.2 before 7.2r11, 7.3 before 7.3r6, and 7.4 before 7.4r3 allow (1) remote attackers to inject arbitrary web script or HTML via vectors involving login pages, and allow (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a support page.
network
juniper CWE-79
4.3
2013-08-16 CVE-2013-5097 Permissions, Privileges, and Access Controls vulnerability in Juniper products
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
network
low complexity
juniper CWE-264
4.0
2013-08-16 CVE-2013-5096 Permissions, Privileges, and Access Controls vulnerability in Juniper products
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804.
network
low complexity
juniper CWE-264
4.0
2013-08-16 CVE-2013-5095 Cross-Site Scripting vulnerability in Juniper products
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka PR 884469.
network
juniper CWE-79
4.3
2013-08-01 CVE-2012-5460 Cross-Site Scripting vulnerability in Juniper products
Cross-site scripting (XSS) vulnerability in the help page in Juniper Secure Access (SA) with IVE OS before 7.1r13, 7.2.x before 7.2r7, and 7.3.x before 7.3r2 allows remote attackers to inject arbitrary web script or HTML via the WWHSearchWordsText parameter.
network
juniper CWE-79
4.3
2013-07-11 CVE-2013-4690 Resource Management Errors vulnerability in Juniper products
Juniper Junos 10.4 before 10.4S13, 11.4 before 11.4R7-S1, 12.1 before 12.1R5-S3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on the SRX1400, SRX3400, and SRX3600 does not properly initialize memory locations used during padding of Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data, aka PR 829536, a related issue to CVE-2003-0001.
network
low complexity
juniper CWE-399
5.0
2013-06-13 CVE-2013-3970 Cryptographic Issues vulnerability in Juniper products
Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.
network
juniper CWE-310
4.3
2013-05-08 CVE-2013-3497 Credentials Management vulnerability in Juniper products
Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
4.7
2013-04-03 CVE-2012-1038 Cross-Site Scripting vulnerability in Juniper Networks Mobility System Software
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter name.
network
juniper CWE-79
4.3
2011-09-02 CVE-2009-5086 Cross-Site Scripting vulnerability in Juniper IDP
Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.2 before 4.2r1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
juniper CWE-79
4.3