|
248281
|
6.5 |
MEDIUM
Network
|
groupsession
|
groupsession
|
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2017-2165
|
2024-11-21 12:23 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248282
|
5.3 |
MEDIUM
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
|
NVD-CWE-noinfo
|
CVE-2017-2311
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248283
|
5.3 |
MEDIUM
Network
|
juniper
|
junos_space
|
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
|
NVD-CWE-noinfo
|
CVE-2017-2310
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248284
|
5.9 |
MEDIUM
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. Th…
|
CWE-200
Information Exposure
|
CVE-2017-2309
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248285
|
6.5 |
MEDIUM
Network
|
juniper
|
junos_space
|
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
|
CWE-611
XXE
|
CVE-2017-2308
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248286
|
6.1 |
MEDIUM
Network
|
juniper
|
junos_space
|
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or pe…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2307
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248287
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
|
CWE-863
Incorrect Authorization
|
CVE-2017-2306
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248288
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allow…
|
CWE-863
Incorrect Authorization
|
CVE-2017-2305
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248289
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet p…
|
CWE-200
Information Exposure
|
CVE-2017-2304
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248290
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D50, 12.1X47 prior to 12.1X47-D40, 12.3 prior to 12.3R13, 12.3X48 prior to 12.3X48-D30, 13.2X51 prior to 13.2X51-D4…
|
NVD-CWE-noinfo
|
CVE-2017-2303
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|