Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2019-0011

Published Jan 15, 2019

The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By con…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0010

Published Jan 15, 2019

An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the error message "mbuf exceed" -- an indication of memory buffer e…

CVSS 7.5 · High

CVE-2019-0009

Published Jan 15, 2019

On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine (PFE). In a virtual chassis (V…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0007

Published Jan 15, 2019

The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting through the device susceptible to a family of attacks which…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-0006

Published Jan 15, 2019

A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwarding Engine manager (fxpc) on all EX, QFX and MX Series dev…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-0005

Published Jan 15, 2019

On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets th…

CVSS 5.3 · Medium

CVE-2019-0001

Published Jan 15, 2019

Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0063

Published Oct 10, 2018

A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust the private Internal routing i…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0060

Published Oct 10, 2018

An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of Service to the dcd process an…

CVSS 5.3 · Medium

CVE-2018-0058

Published Oct 10, 2018

Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device to reboot. The issue is specific to the processing of Broad…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0057

Published Oct 10, 2018

On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0056

Published Oct 10, 2018

If a duplicate MAC address is learned by two different interfaces on an MX Series device, the MAC address learning function correctly flaps between the interfaces. However, the La…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0055

Published Oct 10, 2018

Receipt of a specially crafted DHCPv6 message destined to a Junos OS device configured as a DHCP server in a Broadband Edge (BBE) environment may result in a jdhcpd daemon crash.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0053

Published Oct 10, 2018

An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full control of the system without au…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-0051

Published Oct 10, 2018

A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allows an attacker to crash MS-PIC, MS-MIC, MS-MPC, MS-DPC or SR…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0050

Published Oct 10, 2018

An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cause RPD to crash. Continued receipt of this malformed MPLS R…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0049

Published Oct 10, 2018

A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of this specifically crafted mali…

CVSS 7.5 · High
evidence mentions
3
Buzz score
21.9

CVE-2018-0048

Published Oct 10, 2018

A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 786 CVEsPage 25 of 32