|
210061
|
7.5 |
HIGH
Network
|
facebook
|
hermes
|
An out-of-bounds read in the JavaScript Interpreter in Facebook Hermes prior to commit 8cb935cd3b2321c46aa6b7ed8454d95c75a7fca0 allows attackers to cause a denial of service attack or possible furthe…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-1915
|
2024-11-21 14:11 |
2020-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
7.2 |
HIGH
Network
|
juniper
|
mist_cloud_ui
|
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML response without inval…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-1677
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
7.2 |
HIGH
Network
|
juniper
|
mist_cloud_ui
|
When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its crypto…
|
NVD-CWE-noinfo
|
CVE-2020-1676
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
8.3 |
HIGH
Network
|
juniper
|
mist_cloud_ui
|
When Security Assertion Markup Language (SAML) authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly process invalid authentication certificates which could allow a malicious ne…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-1675
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
6.6 |
MEDIUM
Physics
|
juniper
|
junos_os_evolved
|
The system console configuration option 'log-out-on-disconnect' In Juniper Networks Junos OS Evolved fails to log out an active CLI session when the console cable is disconnected. This could allow a …
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-1666
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
6.5 |
MEDIUM
Adjacent
|
juniper
|
junos
|
On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in a Virtual Chassis configuration, receipt of a stream of specific layer 2 frames can cause high CPU load, which could l…
|
NVD-CWE-noinfo
|
CVE-2020-1689
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
6.5 |
MEDIUM
Local
|
juniper
|
junos
|
On Juniper Networks SRX Series and NFX Series, a local authenticated user with access to the shell may obtain the Web API service private key that is used to provide encrypted communication between t…
|
NVD-CWE-noinfo
|
CVE-2020-1688
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
6.5 |
MEDIUM
Adjacent
|
juniper
|
junos
|
On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in (Ethernet VPN) EVPN-(Virtual Extensible LAN) VXLAN configuration, receipt of a stream of specific VXLAN encapsulated l…
|
NVD-CWE-noinfo
|
CVE-2020-1687
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
7.5 |
HIGH
Network
|
juniper
|
junos
|
On Juniper Networks Junos OS devices, receipt of a malformed IPv6 packet may cause the system to crash and restart (vmcore). This issue can be trigged by a malformed IPv6 packet destined to the Routi…
|
NVD-CWE-noinfo
|
CVE-2020-1686
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
5.8 |
MEDIUM
Network
|
juniper
|
junos
|
When configuring stateless firewall filters in Juniper Networks EX4600 and QFX 5000 Series devices using Virtual Extensible LAN protocol (VXLAN), the discard action will fail to discard traffic under…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-1685
|
2024-11-21 14:11 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|