imPC@ndo EN

Vulnerabilità Juniper

1105 CVE

CVE-2023-36846
Sfruttata Media 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to user.php that doesn't …

juniper junos
0.94EPSS
CVE-2023-36845
Sfruttata Critica 9.8

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remotely execute code. Using a crafted request which sets the variable PHPRC an attac…

juniper junos
0.94EPSS
CVE-2023-36844
Sfruttata Media 5.3

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted request an attacker is able to modify …

juniper junos
0.91EPSS
CVE-2023-36847
Sfruttata Media 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on EX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to installAppPackage.php…

juniper junos
0.85EPSS
CVE-2015-7755
Sfruttata Critica 9.8

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15b, 6.3.0r16 before 6.3.0r16b, 6.3.0r17 before 6.3.0r17b, 6.3.0r18 before 6.3.0r18b, 6.3.0r19 before 6.3.0r19b, …

juniper screenos
0.61EPSS
CVE-2020-1631
Sfruttata Alta 8.8

A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local file inclusion (LFI) …

juniper junos
0.05EPSS
CVE-2025-21590
Sfruttata Media 4.4

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is able to inject arbitrar…

juniper junos
0.02EPSS
CVE-2023-36851
Sfruttata Media 5.3

A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph…

juniper junos
0.01EPSS
CVE-2022-42889
Critica 9.8

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringL…

apache commons_text · juniper security_threat_response_manager · netapp bluexp
1.00EPSS
CVE-2019-11358
Media 6.1

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Obje…

backdropcms backdrop · debian debian_linux · drupal drupal · fedoraproject fedora · e altri 101
0.87EPSS
CVE-2009-1185
Alta 7.2

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · juniper ctpview · e altri 5
0.82EPSS
CVE-2004-0230
Media 5.0

TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-li…

juniper junos · mcafee network_data_loss_prevention · microsoft windows_2000 · microsoft windows_98 · e altri 8
0.80EPSS
CVE-2020-10188
Critica 9.8

utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

arista eos · debian debian_linux · fedoraproject fedora · juniper junos · e altri 2
0.74EPSS
CVE-2008-0960
Alta 10.0

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.…

juniper session_and_resource_control · juniper src_pe
0.69EPSS
CVE-2006-2086
Alta 7.5

Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, all…

juniper junipersetup_control
0.67EPSS
CVE-2016-1286
Alta 8.6

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · isc bind · e altri 10
0.62EPSS
CVE-2016-1285
Media 6.8

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · isc bind · e altri 10
0.59EPSS
CVE-2014-9708
Media 5.0

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

embedthis appweb · juniper junos · oracle enterprise_communications_broker
0.56EPSS
CVE-2017-3145
Alta 7.5

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.…

debian debian_linux · isc bind · juniper junos · netapp data_ontap_edge · e altri 6
0.28EPSS
CVE-2016-7103
Media 6.1

Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

debian debian_linux · fedoraproject fedora · jqueryui jquery_ui · juniper junos · e altri 9
0.23EPSS
CVE-2026-21902
Critica 9.8

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly d…

juniper junos_os_evolved
0.18EPSS
CVE-2024-21591
Critica 9.8

An Out-of-bounds Write vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS), or Remote Code Execution (RCE) and obtain root privileges on the devic…

juniper junos
0.18EPSS
CVE-2023-4481
Alta 7.5

An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When certain specific crafted BGP UPDATE me…

juniper junos · juniper junos_os_evolved
0.15EPSS
CVE-2013-6618
Alta 9.0

jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.

juniper junos
0.11EPSS
CVE-2015-0501
Media 5.7

Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.

canonical ubuntu_linux · debian debian_linux · juniper junos_space · mariadb mariadb · e altri 10
0.10EPSS