Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

ScreenOS: Stored Cross-Site Scripting (XSS) vulnerability

Disclosure Date: October 10, 2018 (last updated November 27, 2024)
A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on administrative user to perform administrative actions on the device. Affected releases are Juniper Networks ScreenOS 6.3.0 versions prior to 6.3.0r26.
0
Attacker Value
Unknown

ScreenOS: Etherleak vulnerability found on ScreenOS device

Disclosure Date: January 10, 2018 (last updated November 26, 2024)
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
0