CVE-2017-2309
- EPSS 0.22%
- Published 30.05.2017 14:29:01
- Last modified 20.04.2025 01:37:25
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
CVE-2017-2308
- EPSS 0.28%
- Published 30.05.2017 14:29:01
- Last modified 20.04.2025 01:37:25
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
CVE-2017-2306
- EPSS 0.62%
- Published 30.05.2017 14:29:00
- Last modified 20.04.2025 01:37:25
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
CVE-2017-2305
- EPSS 0.27%
- Published 30.05.2017 14:29:00
- Last modified 20.04.2025 01:37:25
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
CVE-2015-2620
- EPSS 0.66%
- Published 16.07.2015 10:59:43
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
CVE-2015-3209
- EPSS 5.35%
- Published 15.06.2015 15:59:00
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
CVE-2015-0501
- EPSS 0.6%
- Published 16.04.2015 16:59:50
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
CVE-2014-6559
- EPSS 0.9%
- Published 15.10.2014 22:55:08
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
CVE-2014-6500
- EPSS 1.43%
- Published 15.10.2014 22:55:06
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-20...
CVE-2014-6496
- EPSS 0.61%
- Published 15.10.2014 22:55:06
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.