Vulnerabilities > Juniper > Screenos

DATE CVE VULNERABILITY TITLE RISK
2018-01-10 CVE-2018-0014 Information Exposure vulnerability in Juniper Screenos
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets.
low complexity
juniper CWE-200
3.3
2017-07-17 CVE-2017-2339 Cross-site Scripting vulnerability in Juniper Screenos 6.3.0
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator.
network
juniper CWE-79
3.5
2017-07-17 CVE-2017-2338 Cross-site Scripting vulnerability in Juniper Screenos 6.3.0
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator.
network
juniper CWE-79
3.5
2017-07-17 CVE-2017-2337 Cross-site Scripting vulnerability in Juniper Screenos 6.3.0
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator.
network
juniper CWE-79
3.5
2017-07-17 CVE-2017-2336 Cross-site Scripting vulnerability in Juniper Screenos 6.3.0
A reflected cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a network based attacker to inject HTML/JavaScript content into the management session of other users including the administrator.
network
juniper CWE-79
3.5
2017-07-17 CVE-2017-2335 Cross-site Scripting vulnerability in Juniper Screenos 6.3.0
A persistent cross site scripting vulnerability in NetScreen WebUI of Juniper Networks Juniper NetScreen Firewall+VPN running ScreenOS allows a user with the 'security' role to inject HTML/JavaScript content into the management session of other users including the administrator.
network
juniper CWE-79
3.5
2016-04-15 CVE-2016-1268 Improper Input Validation vulnerability in Juniper Screenos 6.3.0
The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a crafted SSL packet.
network
low complexity
juniper CWE-20
7.8
2016-01-08 CVE-2015-7754 Improper Input Validation vulnerability in Juniper Screenos 6.3.0
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.
network
juniper CWE-20
critical
9.3
2015-12-19 CVE-2015-7756 Cryptographic Issues vulnerability in Juniper Screenos
The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 makes it easier for remote attackers to discover the plaintext content of VPN sessions by sniffing the network for ciphertext data and conducting an unspecified decryption attack.
network
low complexity
juniper CWE-310
5.0
2015-12-19 CVE-2015-7755 Improper Authentication vulnerability in Juniper Screenos 6.3.0
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, and 6.3.0r20 before 6.3.0r21 allows remote attackers to obtain administrative access by entering an unspecified password during a (1) SSH or (2) TELNET session.
network
low complexity
juniper CWE-287
critical
10.0