imPC@ndo EN

Vulnerabilità Juniper

1105 CVE

CVE-2007-5560
Alta 10.0

Heap-based buffer overflow in the Juniper HTTP Service allows remote attackers to execute arbitrary code via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a w…

juniper http_service
0.04EPSS
CVE-2018-0016
Critica 9.8

Receipt of a specially crafted Connectionless Network Protocol (CLNP) datagram destined to an interface of a Junos OS device may result in a kernel crash or lead to remote code execution. Devices are only vulnerable to the specially crafted CLNP datagram if 'c…

juniper junos
0.04EPSS
CVE-2014-3411
Alta 10.0

Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.

juniper network_and_security_manager_software · juniper nsm3000 · juniper nsmexpress
0.04EPSS
CVE-2004-0467
Media 5.0

Juniper JUNOS 5.x through JUNOS 7.x allows remote attackers to cause a denial of service (routing disabled) via a large number of MPLS packets, which are not filtered or verified before being sent to the Routing Engine, which reduces the speed at which other p…

juniper junos
0.04EPSS
CVE-2013-6013
Media 6.8

Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 12.1X45-D10 on SRX devices, when using telnet pass-through authentication on the firewall, might allow remote at…

juniper junos
0.04EPSS
CVE-2015-7754
Alta 8.1

Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.

juniper screenos
0.04EPSS
CVE-2015-5362
Alta 9.3

The BFD daemon in Juniper Junos OS 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D15, 13.2 before 13.2R8, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X50 before 14.1X50-D85, 14.1…

juniper junos
0.04EPSS
CVE-2016-4929
Alta 8.8

Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.

juniper junos_space
0.04EPSS
CVE-2018-0037
Critica 9.8

Junos OS routing protocol daemon (RPD) process may crash and restart or may lead to remote code execution while processing specific BGP NOTIFICATION messages. By continuously sending crafted BGP NOTIFICATION messages, an attacker can repeatedly crash the RPD p…

juniper junos
0.04EPSS
CVE-2009-4643
Alta 10.0

Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Access Client 4.72.11421.0 and other products, allows remote attackers to execute arbitrary code via a long string in a malformed DSSETUPSERVICE_…

juniper odyssey_access_client
0.04EPSS
CVE-2007-6372
Alta 7.8

Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that trigger session flapping.

juniper junos
0.04EPSS
CVE-2017-2345
Critica 9.8

On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and restart by sending a crafted SNMP packet. Repeated crashes of the snmpd daemon can result in a partial denial of s…

juniper junos
0.04EPSS
CVE-2014-0618
Alta 7.8

Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to …

juniper junos · juniper srx100 · juniper srx110 · juniper srx1400 · e altri 9
0.04EPSS
CVE-2002-1547
Media 5.0

Netscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command Shell (SCS) management interface, as demonstrated via certain CRC32 exploits, a different vulnerability than CV…

juniper netscreen_screenos
0.04EPSS
CVE-2014-2842
Alta 7.8

Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.

juniper screenos
0.03EPSS
CVE-2014-3817
Alta 7.8

Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to …

juniper junos · juniper srx100 · juniper srx110 · juniper srx1400 · e altri 9
0.03EPSS
CVE-2021-25220
Media 6.8

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to …

fedoraproject fedora · isc bind · juniper junos · netapp h300e_firmware · e altri 8
0.03EPSS
CVE-2004-0468
Media 5.0

Memory leak in Juniper JUNOS Packet Forwarding Engine (PFE) allows remote attackers to cause a denial of service (memory exhaustion and device reboot) via certain IPv6 packets.

juniper junos
0.03EPSS
CVE-2004-1446
Media 5.0

Unknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device reboot or hang) via a crafted SSH v1 packet.

juniper netscreen_screenos
0.03EPSS
CVE-2019-0001
Alta 7.5

Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion loop in the Broadband Edge subscriber management daemon (bbe-smgd), and lead to high CPU usage and a crash of the bbe-smgd service. Repeate…

fedoraproject fedora · juniper junos
0.03EPSS
CVE-2002-2223
Media 5.1

Buffer overflow in NetScreen-Remote 8.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly including (1) a large Security Parameter Index (SPI) field, (2) …

juniper netscreen_remote_security_client · juniper netscreen_remote_vpn_client
0.03EPSS
CVE-2014-6495
Media 4.3

Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.

juniper junos_space · mariadb mariadb · oracle mysql · oracle solaris · e altri 4
0.03EPSS
CVE-2014-6380
Alta 7.8

Juniper Junos 11.4 before R11, 12.1 before R9, 12.1X44 before D30, 12.1X45 before D20, 12.1X46 before D15, 12.1X47 before D10, 12.2 before R8, 12.2X50 before D70, 12.3 before R6, 13.1 before R4, 13.1X49 before D55, 13.1X50 before D30, 13.2 before R4, 13.2X50 b…

juniper junos
0.03EPSS
CVE-2016-4921
Alta 7.5

By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the inability to store next hop information for legitimate traffic. In extreme cases, the crafted IPv6 traffic may r…

juniper junos
0.03EPSS
CVE-2018-0048
Alta 7.5

A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhaustion condition on the device. This can have an adverse impact on the system per…

juniper junos
0.03EPSS