|
252341
|
7.8 |
HIGH
Local
|
jasdf
|
screensavers
|
Untrusted search path vulnerability in screensaver installers (jasdf_01.exe, jasdf_02.exe, jasdf_03.exe, jasdf_04.exe, jasdf_05.exe, scramble_setup.exe, clock_01_setup.exe, clock_02_setup.exe) availa…
|
CWE-426
Untrusted Search Path
|
CVE-2017-2176
|
2024-11-21 12:23 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252342
|
6.5 |
MEDIUM
Network
|
groupsession
|
groupsession
|
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2017-2165
|
2024-11-21 12:23 |
2017-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252343
|
5.3 |
MEDIUM
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
|
NVD-CWE-noinfo
|
CVE-2017-2311
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252344
|
5.3 |
MEDIUM
Network
|
juniper
|
junos_space
|
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
|
NVD-CWE-noinfo
|
CVE-2017-2310
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252345
|
5.9 |
MEDIUM
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. Th…
|
CWE-200
Information Exposure
|
CVE-2017-2309
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252346
|
6.5 |
MEDIUM
Network
|
juniper
|
junos_space
|
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
|
CWE-611
XXE
|
CVE-2017-2308
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252347
|
6.1 |
MEDIUM
Network
|
juniper
|
junos_space
|
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or pe…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2307
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252348
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
|
CWE-863
Incorrect Authorization
|
CVE-2017-2306
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252349
|
8.8 |
HIGH
Network
|
juniper
|
junos_space
|
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allow…
|
CWE-863
Incorrect Authorization
|
CVE-2017-2305
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252350
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet p…
|
CWE-200
Information Exposure
|
CVE-2017-2304
|
2024-11-21 12:23 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|