Vulnerabilities > Netscreen
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-08-23 | CVE-2005-2640 | Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid. | 5.0 |
2004-11-23 | CVE-2004-0347 | Cross-Site Scripting vulnerability in NetScreen SA 5000 Series delhomepage.cgi Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter. network netscreen | 6.0 |
2002-12-31 | CVE-2002-2266 | Denial Of Service vulnerability in NetScreen H.323 Control Session NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not time out for 36 hours. | 5.0 |
2002-12-31 | CVE-2002-2234 | Configuration vulnerability in Netscreen Screenos NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests. | 4.3 |
2001-02-12 | CVE-2001-0007 | Unspecified vulnerability in Netscreen Screen OS Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface. | 5.0 |