VendorsJuniperjunos21.2
Vulnerabilities

Juniper Junos 21.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

244CVEs
CVE-2022-22237
Junos OS: Peers not configured for TCP-AO can establish a BGP or LDP session even if authentication is configured locally
Published 2022-10-18 · Modified
6.5EPSS 0.004
CVE-2022-22168
Junos OS: vMX and MX150: Specific packets might cause a memory leak and eventually an FPC reboot
Published 2022-01-19 · Modified
6.5EPSS 0.004
CVE-2022-22196
Junos OS and Junos OS Evolved: The rpd CPU spikes to 100% after a malformed ISIS TLV has been received
Published 2022-04-14 · Modified
6.5EPSS 0.004
CVE-2022-22179
Junos OS: jdhcpd crashes upon receiving a specific DHCP packet
Published 2022-01-19 · Modified
6.5EPSS 0.004
CVE-2022-22172
Junos OS and Junos OS Evolved: An l2cpd memory leak can occur when specific LLDP packets are received leading to a DoS
Published 2022-01-19 · Modified
6.5EPSS 0.004
CVE-2022-22191
Junos OS: EX4300: PFE Denial of Service (DoS) upon receipt of a flood of specific ARP traffic
Published 2022-04-14 · Modified
6.5EPSS 0.004
CVE-2022-22160
Junos OS: MX Series: The bbe-smgd process crashes if an unsupported configuration exists and a PPPoE client sends a specific message
Published 2022-01-19 · Modified
6.5EPSS 0.004
CVE-2022-22217
Junos OS: QFX10K Series: Denial of Service (DoS) upon receipt of crafted MLD packets on multi-homing ESI in VXLAN
Published 2022-07-20 · Modified
6.5EPSS 0.003
CVE-2024-21600
Junos OS: PTX Series: In an FTI scenario MPLS packets hitting reject next-hop will cause a host path wedge condition
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2023-44183
Junos OS: QFX5000 Series, EX4600 Series: In a VxLAN scenario an adjacent attacker within the VxLAN sending genuine packets may cause a DMA memory leak to occur.
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2022-22210
Junos OS: QFX5000 Series and MX Series: An l2alm crash leading to an FPC crash can be observed in VxLAN scenario
Published 2022-07-20 · Modified
6.5EPSS 0.003
CVE-2023-1697
Junos OS: QFX10000 Series, PTX1000 Series: The dcpfe process will crash when a malformed ethernet frame is received
Published 2023-04-17 · Modified
6.5EPSS 0.003
CVE-2022-22230
Junos OS and Junos OS Evolved: RPD crash upon receipt of specific OSPFv3 LSAs
Published 2022-10-18 · Modified
6.5EPSS 0.003
CVE-2022-22250
Junos OS and Junos OS Evolved: An FPC crash might be seen due to an EVPN MAC entry moving from local to remote
Published 2022-10-18 · Modified
6.5EPSS 0.003
CVE-2023-22405
Junos OS: QFX5k Series, EX46xx Series: MAC limiting feature stops working after PFE restart or device reboot
Published 2023-01-12 · Modified
6.5EPSS 0.003
CVE-2023-22406
Junos OS and Junos OS Evolved: A memory leak which will ultimately lead to an rpd crash will be observed when a peer interface flaps continuously in a Segment Routing scenario using OSPF
Published 2023-01-12 · Modified
6.5EPSS 0.003
CVE-2023-22414
Junos OS: PTX Series and QFX10000 Series: An FPC memory leak is observed when specific EVPN VXLAN Multicast packets are processed
Published 2023-01-12 · Modified
6.5EPSS 0.003
CVE-2023-28959
Junos OS: QFX10002: PFE wedges and restarts upon receipt of specific malformed packets
Published 2023-04-17 · Modified
6.5EPSS 0.003
CVE-2023-28970
Junos OS: JRR200: Kernel crash upon receipt of a specific packet
Published 2023-04-17 · Modified
6.5EPSS 0.003
CVE-2023-28981
Junos OS and Junos OS Evolved: If malformed IPv6 router advertisements are received, memory corruption will occur which causes an rpd crash
Published 2023-04-17 · Modified
6.5EPSS 0.003
CVE-2023-36834
Junos OS: SRX 4600 and SRX 5000 Series: The receipt of specific genuine packets by SRXes configured for L2 transparency will cause a DoS
Published 2023-07-14 · Modified
6.5EPSS 0.003
CVE-2023-36848
Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet
Published 2023-07-14 · Modified
6.5EPSS 0.003
CVE-2023-36850
Junos OS: MX Series: An MPC will crash upon receipt of a malformed CFM packet.
Published 2023-07-14 · Modified
6.5EPSS 0.003
CVE-2023-22395
Junos OS: In an MPLS scenario the processing of specific packets to the device causes a buffer leak and ultimately a loss of connectivity
Published 2023-01-12 · Modified
6.5EPSS 0.003
CVE-2022-22238
Junos OS and Junos OS Evolved: The rpd process will crash when a malformed incoming RESV message is processed
Published 2022-10-18 · Modified
6.5EPSS 0.003
CVE-2024-21599
Junos OS: MX Series: MPC3E memory leak with PTP configuration
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2023-36842
Junos OS: jdhcpd will hang on receiving a specific DHCP packet
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2024-21617
Junos OS: BGP flap on NSR-enabled devices causes memory leak
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2023-22392
Junos OS: PTX Series and QFX10000 Series: Received flow-routes which aren't installed as the hardware doesn't support them, lead to an FPC heap memory leak
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2024-21587
Junos OS: MX Series: Memory leak in bbe-smgd process if BFD liveness detection for DHCP subscribers is enabled
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2024-21613
Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash
Published 2024-01-12 · Modified
6.5EPSS 0.003
CVE-2023-44203
Junos OS: QFX5000 Series, EX2300, EX3400, EX4100, EX4400 and EX4600: Packet flooding will occur when IGMP traffic is sent to an isolated VLAN
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2023-36839
Junos OS and Junos OS Evolved: An l2cpd crash will occur when specific LLDP packets are received
Published 2023-10-12 · Modified
6.5EPSS 0.003
CVE-2024-30391
Junos OS: MX Series with SPC3, and SRX Series: When IPsec authentication is configured with "hmac-sha-384" and "hmac-sha-512" no authentication of traffic is performed
Published 2024-04-12 · Analyzed
6.3EPSS 0.004
CVE-2024-39532
Junos OS and Junos OS Evolved: Confidential information in logs can be accessed by another user
Published 2024-07-11 · Analyzed
6.3EPSS 0.002
CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Published 2019-04-19 · Modified
6.11 PoCEPSS 0.872
CVE-2016-7103
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
Published 2017-03-15 · Modified
6.1EPSS 0.226
CVE-2020-7656
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "<script>" HTML tags that contain a whitespace character, i.e: "</script >", which results in the enclosed script logic to be executed.
Published 2020-05-19 · Modified
6.11 PoCEPSS 0.063
CVE-2022-22242
Junos OS: Cross-site Scripting (XSS) vulnerability in J-Web
Published 2022-10-18 · Modified
6.1EPSS 0.028
CVE-2024-39528
Junos OS and Junos OS Evolved: Concurrent deletion of a routing-instance and receipt of an SNMP request cause an RPD crash
Published 2024-07-11 · Modified
6.0EPSS 0.003
← Prev5 / 7Next →