Vulnerability index

Browse CVEs

1,019 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Junos HIGH 7.5
CVE-2019-0013

The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is received. While RPD restarts after a…

Patch available
Fix from $1,950 2019-01-15
Junos HIGH 7.5
CVE-2019-0014

On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator) process which causes all int…

Patch available
Fix from $1,950 2019-01-15
Junos MEDIUM 6.5
CVE-2019-0011

The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destin…

Mitigation only
Fix from $1,600 2019-01-15
Junos Space MEDIUM 6.5
CVE-2019-0016

A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privileges through crafted Ajax int…

Mitigation only
Fix from $1,600 2019-01-15
Junos MEDIUM 5.5
CVE-2019-0009

On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and the packet forwarding engine …

Mitigation only
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.5
CVE-2019-0021

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be…

Fix: 5.0.4+
Fix from $1,600 2019-01-15
Junos MEDIUM 5.4
CVE-2019-0015

A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted.…

Mitigation only
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0018

A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated user to inject arbitrary scri…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0023

A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user to inject arbitrary script an…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0024

A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary sc…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0025

A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticated user to inject arbitrary sc…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0026

A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary scrip…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.4
CVE-2019-0027

A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenticated user to inject arbitrar…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Junos CRITICAL 9.8
CVE-2019-0002

On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with other actions might not take …

Mitigation only
Fix from $2,300 2019-01-15
Junos MEDIUM 5.9
CVE-2019-0003

When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec conf…

Mitigation only
Fix from $1,600 2019-01-15
Advanced Threat Prevention MEDIUM 5.5
CVE-2019-0004

On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys are used for performing critica…

Fix: 5.0.3+
Fix from $1,600 2019-01-15
Junos MEDIUM 5.3
CVE-2019-0005

On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This i…

Mitigation only
Fix from $1,600 2019-01-15
Junos HIGH 7.5
CVE-2018-0058

Receipt of a specially crafted IPv6 exception packet may be able to trigger a kernel crash (vmcore), causing the device to reboot. The issue is speci…

Mitigation only
Fix from $1,950 2018-10-10
Junos HIGH 7.5
CVE-2018-0062

A Denial of Service vulnerability in J-Web service may allow a remote unauthenticated user to cause Denial of Service which may prevent other users t…

Mitigation only
Fix from $1,950 2018-10-10
Junos MEDIUM 6.5
CVE-2018-0063

A vulnerability in the IP next-hop index database in Junos OS 17.3R3 may allow a flood of ARP requests, sent to the management interface, to exhaust …

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0060

An improper input validation weakness in the device control daemon process (dcd) of Juniper Networks Junos OS allows an attacker to cause a Denial of…

Mitigation only
Fix from $1,600 2018-10-10
Netscreen Screenos MEDIUM 5.4
CVE-2018-0059

A persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web scrip…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.3
CVE-2018-0061

A denial of service vulnerability in the telnetd service on Junos OS allows remote unauthenticated users to cause high CPU usage which may affect sys…

Mitigation only
Fix from $1,600 2018-10-10
Junos CRITICAL 9.6
CVE-2018-0057

On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specif…

Mitigation only
Fix from $2,300 2018-10-10
Junos HIGH 8.1
CVE-2018-0052

If RSH service is enabled on Junos OS and if the PAM authentication is disabled, a remote unauthenticated attacker can obtain root access to the devi…

Mitigation only
Fix from $1,950 2018-10-10
Junos HIGH 7.5
CVE-2018-0049

A NULL Pointer Dereference vulnerability in Juniper Networks Junos OS allows an attacker to cause the Junos OS kernel to crash. Continued receipt of …

Mitigation only
Fix from $1,950 2018-10-10
Junos MEDIUM 6.8
CVE-2018-0053

An authentication bypass vulnerability in the initial boot sequence of Juniper Networks Junos OS on vSRX Series may allow an attacker to gain full co…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 6.5
CVE-2018-0054

On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can ca…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0050

An error handling vulnerability in Routing Protocols Daemon (RPD) of Juniper Networks Junos OS allows an attacker to cause RPD to crash. Continued re…

Mitigation only
Fix from $1,600 2018-10-10
Junos MEDIUM 5.9
CVE-2018-0051

A Denial of Service vulnerability in the SIP application layer gateway (ALG) component of Junos OS based platforms allows an attacker to crash MS-PIC…

Mitigation only
Fix from $1,600 2018-10-10