Vulnerabilities > Netscreen

DATE CVE VULNERABILITY TITLE RISK
2005-08-23 CVE-2005-2640 Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when the username is invalid.
network
low complexity
neoteris juniper netscreen
5.0
2004-11-23 CVE-2004-0347 Cross-Site Scripting vulnerability in NetScreen SA 5000 Series delhomepage.cgi
Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter.
network
netscreen
6.0
2002-12-31 CVE-2002-2266 Denial Of Service vulnerability in NetScreen H.323 Control Session
NetScreen ScreenOS 2.8 through 4.0, when forwarding H.323 or Netmeeting traffic, allows remote attackers to cause a denial of service (firewall session table consumption) by establishing multiple half-open H.323 sessions, which are not cleaned up on garbage removal and do not time out for 36 hours.
network
low complexity
netscreen
5.0
2002-12-31 CVE-2002-2234 Configuration vulnerability in Netscreen Screenos
NetScreen ScreenOS before 4.0.1 allows remote attackers to bypass the Malicious-URL blocking feature by splitting the URL into fragmented IP requests.
network
netscreen CWE-16
4.3
2001-02-12 CVE-2001-0007 Unspecified vulnerability in Netscreen Screen OS
Buffer overflow in NetScreen Firewall WebUI allows remote attackers to cause a denial of service via a long URL request to the web administration interface.
network
low complexity
netscreen
5.0