VendorsJuniperjunos15.1x49
Vulnerabilities

Juniper Junos 15.1x49

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

134CVEs
CVE-2017-2303
On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D50, 12.1X47 prior to 12.1X47-D40, 12.3 prior to 12.3R13, 12.3X48 prior to 12.3X48-D30, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R5, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D30 or 15.1X49-D40, 15.1X53 prior to 15.1X53-D35, and where RIP is enabled, certain RIP advertisements received by the router may cause the RPD daemon to crash resulting in a denial of service condition.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2017-2301
On Juniper Networks products or platforms running Junos OS 11.4 prior to 11.4R13-S3, 12.1X46 prior to 12.1X46-D60, 12.3 prior to 12.3R12-S2 or 12.3R13, 12.3X48 prior to 12.3X48-D40, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D12 or 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R7, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D60, 15.1X53 prior to 15.1X53-D30 and DHCPv6 enabled, when a crafted DHCPv6 packet is received from a subscriber, jdhcpd daemon crashes and restarts. Repeated crashes of the jdhcpd process may constitute an extended denial of service condition for subscribers attempting to obtain IPv6 addresses.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2017-2302
On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D55, 12.1X47 prior to 12.1X47-D45, 12.3R13 prior to 12.3R13, 12.3X48 prior to 12.3X48-D35, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D40, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R6, 15.1 prior to 15.1F2 or 15.1R1, 15.1X49 prior to 15.1X49-D20 where the BGP add-path feature is enabled with 'send' option or with both 'send' and 'receive' options, a network based attacker can cause the Junos OS rpd daemon to crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition.
Published 2017-05-30 · Modified
7.8EPSS 0.021
CVE-2014-6450
Juniper Junos OS before 11.4R12-S4, 12.1X44 before 12.1X44-D41, 12.1X46 before 12.1X46-D26, 12.1X47 before 12.1X47-D11/D15, 12.2 before 12.2R9, 12.2X50 before 12.2X50-D70, 12.3 before 12.3R8, 12.3X48 before 12.3X48-D10, 12.3X50 before 12.3X50-D42, 13.1 before 13.1R4-S3, 13.1X49 before 13.1X49-D42, 13.1X50 before 13.1X50-D30, 13.2 before 13.2R6, 13.2X51 before 13.2X51-D26, 13.2X52 before 13.2X52-D15, 13.3 before 13.3R3-S3, 14.1 before 14.1R3, 14.2 before 14.2R1, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D10, when configured for IPv6, allow remote attackers to cause a denial of service (mbuf chain corruption and kernel panic) via crafted IPv6 packets.
Published 2015-10-16 · Modified
7.8EPSS 0.019
CVE-2015-7752
The SSH server in Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D10, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D35, 13.3 before 13.3R6, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D25, 14.2 before 14.2R3, 15.1 before 15.1R1, and 15.1X49 before 15.1X49-D20 allows remote attackers to cause a denial of service (CPU consumption) via unspecified SSH traffic.
Published 2015-10-19 · Modified
7.8EPSS 0.019
CVE-2019-0052
SRX Series: srxpfe process crash while JSF/UTM module parses specific HTTP packets
Published 2019-07-11 · Modified
7.8EPSS 0.018
CVE-2016-1263
Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, 14.2 before 14.2R6, 15.1 before 15.1F2-S5, 15.1F4 before 15.1F4-S2, 15.1R before 15.1R2-S3, 15.1 before 15.1R3, and 15.1X49 before 15.1X49-D40 allow remote attackers to cause a denial of service (kernel crash) via a crafted UDP packet destined to the interface IP address of a 64-bit OS device.
Published 2016-09-09 · Modified
7.8EPSS 0.014
CVE-2018-0020
Junos OS: rpd daemon cores due to malformed BGP UPDATE packet
Published 2018-04-11 · Modified
7.8EPSS 0.013
CVE-2019-0053
Junos OS: Insufficient validation of environment variables in telnet client may lead to stack-based buffer overflow
Published 2019-07-11 · Modified
7.8EPSS 0.006
CVE-2017-2344
Junos: Buffer overflow in sockets library
Published 2017-07-14 · Modified
7.8EPSS 0.005
CVE-2017-10602
Junos OS: buffer overflow vulnerability in Junos CLI
Published 2017-07-14 · Modified
7.8EPSS 0.004
CVE-2018-0024
Junos OS: A privilege escalation vulnerability exists where authenticated users with shell access can become root
Published 2018-07-11 · Modified
7.8EPSS 0.004
CVE-2019-0061
Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
Published 2019-10-09 · Modified
7.8EPSS 0.004
CVE-2016-1271
Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.3R7, 14.1 before 14.1R6, 14.2 before 14.2R4, 15.1 before 15.1R1 or 15.1F2, and 15.1X49 before 15.1X49-D15 allow local users to gain privileges via crafted combinations of CLI commands and arguments, a different vulnerability than CVE-2015-3003, CVE-2014-3816, and CVE-2014-0615.
Published 2016-04-15 · Modified
7.8EPSS 0.003
CVE-2018-15504
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
Published 2018-08-18 · Modified
7.5EPSS 0.028
CVE-2019-0010
Junos OS: SRX Series: Crafted HTTP traffic may cause UTM to consume all mbufs, leading to Denial of Service
Published 2019-01-15 · Modified
7.5EPSS 0.027
CVE-2018-0062
Junos OS: Denial of Service in J-Web
Published 2018-10-10 · Modified
7.5EPSS 0.023
CVE-2017-2313
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition. The affected Junos OS versions are: 15.1 prior to 15.1F2-S15, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D78, 15.1X49-D80; 15.1X53 prior to 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 prior to 16.1R3-S3, 16.1R4; 16.2 prior to 16.2R1-S3, 16.2R2; Releases prior to Junos OS 15.1 are unaffected by this vulnerability. 17.1R1, 17.2R1, and all subsequent releases have a resolution for this vulnerability.
Published 2017-04-24 · Modified
7.5EPSS 0.023
CVE-2018-15505
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Published 2018-08-18 · Modified
7.5EPSS 0.022
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2017-2347
Junos: Denial of Service vulnerability in rpd daemon
Published 2017-07-14 · Modified
7.5EPSS 0.019
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2017-10614
Junos OS: A remote unauthenticated attacker can consume large amounts of CPU and/or memory through telnetd
Published 2017-10-13 · Modified
7.5EPSS 0.017
CVE-2019-0013
Junos OS: RPD crash upon receipt of malformed PIM packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0012
Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2018-0051
Junos OS: Denial of Service vulnerability in MS-PIC, MS-MIC, MS-MPC, MS-DPC and SRX flow daemon (flowd) related to SIP ALG
Published 2018-10-10 · Modified
7.5EPSS 0.016
CVE-2018-0018
SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.
Published 2018-04-11 · Modified
7.5EPSS 0.016
CVE-2019-0044
Junos OS: SRX5000 series: Kernel crash (vmcore) upon receipt of a specific packet on fxp0 interface
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0060
Junos OS: SRX Series: flowd process crash due to processing of specific transit IP packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2017-10619
Junos: SRX cluster denial of service vulnerability in flowd due to multicast packets
Published 2017-10-13 · Modified
7.5EPSS 0.013
CVE-2017-2314
Junos: RPD crash due to malformed BGP OPEN message
Published 2017-07-14 · Modified
7.5EPSS 0.013
CVE-2017-2348
Junos OS: jdhcpd daemon crash due to invalid IPv6 UDP packets
Published 2017-07-14 · Modified
7.5EPSS 0.013
CVE-2020-1657
Junos OS: SRX Series: An attacker sending spoofed packets to IPSec peers may cause a Denial of Service.
Published 2020-10-16 · Modified
7.5EPSS 0.013
CVE-2019-0050
Junos OS: SRX1500: Denial of service due to crash of srxpfe process under heavy traffic conditions.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2021-0261
Junos OS: Denial of Service vulnerability in J-Web and web based (HTTP/HTTPS) services caused by a high number of specific requests
Published 2021-04-22 · Modified
7.5EPSS 0.011
← Prev2 / 4Next →