VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2018-0027
Junos OS: Receipt of malformed RSVP packet may lead to RPD denial of service
Published 2018-07-11 · Modified
7.5EPSS 0.024
CVE-2018-0050
Junos OS: Receipt of a malformed MPLS RSVP packet leads to a Routing Protocols Daemon (RPD) crash.
Published 2018-10-10 · Modified
7.5EPSS 0.023
CVE-2018-0062
Junos OS: Denial of Service in J-Web
Published 2018-10-10 · Modified
7.5EPSS 0.023
CVE-2017-2313
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition. The affected Junos OS versions are: 15.1 prior to 15.1F2-S15, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D78, 15.1X49-D80; 15.1X53 prior to 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 prior to 16.1R3-S3, 16.1R4; 16.2 prior to 16.2R1-S3, 16.2R2; Releases prior to Junos OS 15.1 are unaffected by this vulnerability. 17.1R1, 17.2R1, and all subsequent releases have a resolution for this vulnerability.
Published 2017-04-24 · Modified
7.5EPSS 0.023
CVE-2018-15505
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 address.
Published 2018-08-18 · Modified
7.5EPSS 0.022
CVE-2018-0049
Junos OS: Receipt of a specifically crafted malicious MPLS packet leads to a Junos kernel crash.
Published 2018-10-10 · Modified
7.5EPSS 0.022
CVE-2017-2347
Junos: Denial of Service vulnerability in rpd daemon
Published 2017-07-14 · Modified
7.5EPSS 0.019
CVE-2019-0003
Junos OS: A flowspec BGP update with a specific term-order causes routing protocol daemon (rpd) process to crash with a core.
Published 2019-01-15 · Modified
7.5EPSS 0.019
CVE-2018-0017
SRX Series: Denial of service vulnerability in flowd daemon on devices configured with NAT-PT
Published 2018-04-11 · Modified
7.5EPSS 0.019
CVE-2017-2300
On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets.
Published 2017-05-30 · Modified
7.5EPSS 0.018
CVE-2017-2304
Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'
Published 2017-05-30 · Modified
7.5EPSS 0.018
CVE-2018-0026
Junos OS: Stateless IP firewall filter rules stop working as expected after reboot or upgrade
Published 2018-07-11 · Modified
7.5EPSS 0.018
CVE-2017-10614
Junos OS: A remote unauthenticated attacker can consume large amounts of CPU and/or memory through telnetd
Published 2017-10-13 · Modified
7.5EPSS 0.017
CVE-2019-0013
Junos OS: RPD crash upon receipt of malformed PIM packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2019-0031
Junos OS: jdhcpd daemon memory consumption Denial of Service when receiving specific IPv6 DHCP packets.
Published 2019-04-10 · Modified
7.5EPSS 0.017
CVE-2019-0014
Junos OS: QFX and PTX Series: FPC process crashes after J-Flow processes a malformed packet
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2018-0032
Junos OS: RPD crash when receiving a crafted BGP UPDATE
Published 2018-07-11 · Modified
7.5EPSS 0.017
CVE-2019-0012
Junos OS: rpd crash on VPLS PE upon receipt of specific BGP message
Published 2019-01-15 · Modified
7.5EPSS 0.017
CVE-2018-0051
Junos OS: Denial of Service vulnerability in MS-PIC, MS-MIC, MS-MPC, MS-DPC and SRX flow daemon (flowd) related to SIP ALG
Published 2018-10-10 · Modified
7.5EPSS 0.016
CVE-2020-1653
Junos OS: Kernel crash (vmcore) or FPC crash due to mbuf leak
Published 2020-07-17 · Modified
7.5EPSS 0.016
CVE-2019-0033
SRX Series: A remote attacker may cause a high CPU Denial of Service to the device when proxy ARP is configured.
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2018-0018
SRX Series: A crafted packet may lead to information disclosure and firewall rule bypass during compilation of IDP policies.
Published 2018-04-11 · Modified
7.5EPSS 0.016
CVE-2019-0044
Junos OS: SRX5000 series: Kernel crash (vmcore) upon receipt of a specific packet on fxp0 interface
Published 2019-04-10 · Modified
7.5EPSS 0.016
CVE-2019-0049
Junos OS: RPD process crashes when BGP peer restarts
Published 2019-07-11 · Modified
7.5EPSS 0.015
CVE-2022-22188
Junos OS: QFX5100/QFX5110/QFX5120/QFX5200/QFX5210/EX4600/EX4650 Series: When storm control profiling is enabled and a device is under an active storm, a Heap-based Buffer Overflow in the PFE will cause a device to hang.
Published 2022-04-14 · Modified
7.5EPSS 0.015
CVE-2020-1640
Junos OS: Receipt of certain genuine BGP packets from any BGP Speaker causes RPD to crash.
Published 2020-07-17 · Modified
7.5EPSS 0.014
CVE-2019-0066
Junos OS: A malformed IPv4 packet received by Junos in an NG-mVPN scenario may cause the routing protocol daemon (rpd) process to core
Published 2019-10-09 · Modified
7.5EPSS 0.014
CVE-2019-0055
Junos OS: SRX Series: An attacker may cause flowd to crash by sending certain valid SIP traffic to a device with SIP ALG enabled.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0060
Junos OS: SRX Series: flowd process crash due to processing of specific transit IP packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2021-31379
Junos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.
Published 2021-10-19 · Modified
7.5EPSS 0.013
CVE-2019-0043
Junos OS: RPD process crashes upon receipt of a specific SNMP packet
Published 2019-04-10 · Modified
7.5EPSS 0.013
CVE-2019-0059
Junos OS: The routing protocol process (rpd) may crash and generate core files upon receipt of specific valid BGP states from a peered host.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2020-1627
Junos OS: vMX and MX150: Denial of Service vulnerability in packet processing
Published 2020-04-08 · Modified
7.5EPSS 0.013
CVE-2020-1638
Junos OS & Junos OS Evolved: A specific IPv4 packet can lead to FPC restart.
Published 2020-04-08 · Modified
7.5EPSS 0.013
CVE-2019-0056
Junos OS: MX Series: An MPC10 Denial of Service (DoS) due to OSPF states transitioning to Down, causes traffic to stop forwarding through the device.
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2021-0227
Junos OS: SRX Series: Denial of Service in J-Web upon receipt of crafted HTTP packets
Published 2021-04-22 · Modified
7.5EPSS 0.013
CVE-2021-0206
Junos OS: NFX Series, SRX Series: PFE may crash upon receipt of specific packet when SSL Proxy is configured.
Published 2021-01-15 · Modified
7.5EPSS 0.013
CVE-2019-0075
Junos OS: SRX Series: Denial of Service vulnerability in srxpfe related to PIM
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2019-0068
Junos OS: SRX Series: Denial of Service vulnerability in flowd due to multicast packets
Published 2019-10-09 · Modified
7.5EPSS 0.013
CVE-2017-10619
Junos: SRX cluster denial of service vulnerability in flowd due to multicast packets
Published 2017-10-13 · Modified
7.5EPSS 0.013
← Prev7 / 20Next →