CVE-2014-2711
https://notcve.org/view.php?id=CVE-2014-2711
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos before 11.4R11, 11.4X27 before 11.4X27.62 (BBE), 12.1 before 12.1R9, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.2 before 12.2R7, 12.3 before 12.3R6, 13.1 before 13.1R4, 13.2 before 13.2R3, and 13.3 before 13.3R1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en J-Web en Juniper Junos en versiones anteriores a 11.4R11, 11.4X27 en versiones anteriores a 11.4X27.62 (BBE), 12.1 en versiones anteriores a 12.1R9, 12.1X44 en versiones anteriores a 12.1X44-D35, 12.1X45 en versiones anteriores a 12.1X45-D25, 12.1X46 en versiones anteriores a 12.1X46-D20, 12.2 en versiones anteriores a 12.2R7, 12.3 en versiones anteriores a 12.3R6, 13.1 en versiones anteriores a 13.1R4, 13.2 en versiones anteriores a 13.2R3 y 13.3 en versiones anteriores a 13.3R1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de vectores no especificados. • http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10619 http://www.securityfocus.com/bid/66770 http://www.securitytracker.com/id/1030061 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-0614
https://notcve.org/view.php?id=CVE-2014-0614
Juniper Junos 13.2 before 13.2R3 and 13.3 before 13.3R1, when PIM is enabled, allows remote attackers to cause a denial of service (kernel panic and crash) via a large number of crafted IGMP packets. Juniper Junos 13.2 anterior a 13.2R3 y 13.3 anterior a 13.3R1, cuando PIM está habilitado, permite a atacantes remotos causar una denegación de servicio (kernel panic y caída) a través de un número grande de paquetes IGMP manipulados. • http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10618 http://secunia.com/advisories/57819 http://securitytracker.com/id?1030062 http://www.securityfocus.com/bid/66762 •
CVE-2014-2712
https://notcve.org/view.php?id=CVE-2014-2712
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos before 10.0S25, 10.4 before 10.4R10, 11.4 before 11.4R11, 12.1 before 12.1R9, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, and 12.2 before 12.2R1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to index.php. Vulnerabilidad de XSS en J-Web en Juniper Junos en versiones anteriores a 10.0S25, 10.4 en versiones anteriores a 10.4R10, 11.4 en versiones anteriores a 11.4R11, 12.1 en versiones anteriores a 12.1R9, 12.1X44 en versiones anteriores a 12.1X44-D30, 12.1X45 en versiones anteriores a 12.1X45-D20, 12.1X46 en versiones anteriores a 12.1X46-D10 y 12.2 en versiones anteriores a 12.2R1 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de parámetros no especificados en index.php. • http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10521 http://www.securityfocus.com/bid/66767 http://www.securitytracker.com/id/1030058 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-2713
https://notcve.org/view.php?id=CVE-2014-2713
Juniper Junos before 11.4R11, 12.1 before 12.1R9, 12.2 before 12.2R7, 12.3R4 before 12.3R4-S3, 13.1 before 13.1R4, 13.2 before 13.2R2, and 13.3 before 13.3R1, as used in MX Series and T4000 routers, allows remote attackers to cause a denial of service (PFE restart) via a crafted IP packet to certain (1) Trio or (2) Cassis-based Packet Forwarding Engine (PFE) modules. Juniper Junos anterior a 11.4R11, 12.1 anterior a 12.1R9, 12.2 anterior a 12.2R7, 12.3R4 anterior a 12.3R4-S3, 13.1 anterior a 13.1R4, 13.2 anterior a 13.2R2 y 13.3 anterior a 13.3R1, utilizado en routers MX Series y T4000, permite a atacantes remotos causar una denegación de servicio (reinicio de PFE) a través de un paquete IP manipulado hacia ciertos módulos (1) Trio o (2) Cassis-based Packet Forwarding Engine (PFE). • http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10621 http://www.securityfocus.com/bid/66764 •
CVE-2014-2714
https://notcve.org/view.php?id=CVE-2014-2714
The Enhanced Web Filtering (EWF) in Juniper Junos before 10.4R15, 11.4 before 11.4R9, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D10, and 12.1X46 before 12.1X46-D10, as used in the SRX Series services gateways, allows remote attackers to cause a denial of service (flow daemon crash and restart) via a crafted URL. Enhanced Web Filtering (EWF) en Juniper Junos anterior a 10.4R15, 11.4 anterior a 11.4R9, 12.1 anterior a 12.1R7, 12.1X44 anterior a 12.1X44-D20, 12.1X45 anterior a 12.1X45-D10 y 12.1X46 anterior a 12.1X46-D10, utilizado en las pasarelas de servicios de la serie SRX, permite a atacantes remotos causar una denegación de servicio (caída de demonio de flujo y reinicio) a través de una URL manipulada. • http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10622 http://secunia.com/advisories/57835 http://securitytracker.com/id?1030060 http://www.securityfocus.com/bid/66760 • CWE-20: Improper Input Validation •