|
247041
|
6.2 |
MEDIUM
Physics
|
juniper
|
junos
|
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured unde…
|
CWE-287
Improper Authentication
|
CVE-2018-0008
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247042
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an impro…
|
CWE-119 CWE-94 CWE-77
Incorrect Access of Indexable Resource ('Range Error') Code Injection Command Injection
|
CVE-2018-0007
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247043
|
5.3 |
MEDIUM
Adjacent
|
juniper
|
junos
|
A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead t…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-0006
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247044
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsy…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-0004
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247045
|
6.5 |
MEDIUM
Adjacent
|
juniper
|
junos
|
A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is acc…
|
NVD-CWE-noinfo
|
CVE-2018-0003
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247046
|
5.9 |
MEDIUM
Network
|
juniper
|
junos
|
On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed through the device results in memory corruption leading to a flowd daemon crash…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0002
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247047
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the …
|
CWE-416
Use After Free
|
CVE-2018-0001
|
2024-11-21 12:37 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247048
|
7.5 |
HIGH
Network
|
cisco
|
node-jose
|
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerabi…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-0114
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247049
|
9.6 |
CRITICAL
Network
|
cisco
|
webex_meetings_server webex_meetings webex_business_suite webex_network_recording_player
|
A vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a remote attacker to execute arbitrary code on the system of a targeted user. The attacke…
|
CWE-20
Improper Input Validation
|
CVE-2018-0104
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247050
|
7.8 |
HIGH
Local
|
cisco
|
webex_meetings_server webex_meetings webex_business_suite webex_network_recording_player
|
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0103
|
2024-11-21 12:37 |
2018-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|