VendorsJuniperjunos_spaceany version
Vulnerabilities

Juniper Junos Space any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2025-59993
Junos Space: Space Node Setting fields are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59994
Junos Space: Quick Template page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59995
Junos Space: Template creation through Definition is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59996
Junos Space: Configuration View page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59985
Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59984
Junos Space: Global Search is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59998
Junos Space: Archive Logs screen is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60000
Junos Space: Generate Report page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60001
Junos Space: Create Quick Template page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60002
Junos Space: Template Definitions page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-60009
Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2017-2309
On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.
Published 2017-05-30 · Modified
5.9EPSS 0.008
CVE-2014-0460
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vectors related to JNDI.
Published 2014-04-16 · Modified
5.8EPSS 0.044
CVE-2015-0501
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
Published 2015-04-16 · Modified
5.7EPSS 0.099
CVE-2017-2311
On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.
Published 2017-05-30 · Modified
5.3EPSS 0.013
CVE-2017-2310
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
Published 2017-05-30 · Modified
5.3EPSS 0.012
CVE-2013-3497
Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Published 2013-05-08 · Modified
4.7EPSS 0.003
CVE-2014-6494
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
Published 2014-10-15 · Modified
4.3EPSS 0.048
CVE-2015-2620
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
Published 2015-07-16 · Modified
4.3EPSS 0.047
CVE-2014-6559
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
Published 2014-10-15 · Modified
4.3EPSS 0.046
CVE-2014-6496
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
Published 2014-10-15 · Modified
4.3EPSS 0.043
CVE-2014-6495
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
Published 2014-10-15 · Modified
4.3EPSS 0.030
CVE-2014-6478
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
Published 2014-10-15 · Modified
4.3EPSS 0.026
CVE-2014-0453
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Security.
Published 2014-04-16 · Modified
4.0EPSS 0.049
← Prev2 / 2