VendorsJuniperjunos_spaceany version
Vulnerabilities

Juniper Junos Space any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

64CVEs
CVE-2014-0429
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Published 2014-04-15 · Modified
10.0EPSS 0.073
CVE-2014-2421
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
Published 2014-04-16 · Modified
10.0EPSS 0.066
CVE-2014-0457
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
Published 2014-04-16 · Modified
10.0EPSS 0.066
CVE-2014-0456
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
Published 2014-04-16 · Modified
10.0EPSS 0.066
CVE-2014-3412
Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors.
Published 2014-05-20 · Modified
10.0EPSS 0.047
CVE-2016-4926
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
Published 2017-03-20 · Modified
9.8EPSS 0.025
CVE-2016-1265
Junos Space: privilege escalation vulnerabilities in Junos Space
Published 2017-10-13 · Modified
9.8EPSS 0.023
CVE-2025-59978
Junos Space: Stored cross-site scripting vulnerability in web application
Published 2025-10-09 · Analyzed
9.4EPSS 0.005
CVE-2016-4929
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
Published 2017-03-20 · Modified
9.0EPSS 0.038
CVE-2017-2306
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.
Published 2017-05-30 · Modified
8.8EPSS 0.016
CVE-2017-2305
On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.
Published 2017-05-30 · Modified
8.8EPSS 0.011
CVE-2016-4928
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
Published 2017-03-20 · Modified
8.8EPSS 0.007
CVE-2025-59975
Junos Space: Flooding device with inbound API calls leads to WebUI and CLI management access DoS
Published 2025-10-09 · Analyzed
8.7EPSS 0.004
CVE-2026-21907
Junos Space: TLS/SSL server supports use of static key ciphers (ssl-static-key-ciphers)
Published 2026-01-15 · Analyzed
8.2EPSS 0.002
CVE-2016-4927
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
Published 2017-03-20 · Modified
8.1EPSS 0.012
CVE-2017-10623
Junos Space: Insufficient verification of cluster messages
Published 2017-10-13 · Modified
8.1EPSS 0.009
CVE-2017-10612
Junos Space: Persistent Cross site scripting in Junos Space
Published 2017-10-13 · Modified
8.0EPSS 0.013
CVE-2018-0012
Junos Space: Local privilege escalation vulnerability in Junos Space
Published 2018-01-10 · Modified
7.8EPSS 0.003
CVE-2015-3209
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
Published 2015-06-15 · Modified
7.5EPSS 0.097
CVE-2014-6500
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6491.
Published 2014-10-15 · Modified
7.5EPSS 0.057
CVE-2014-6491
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SERVER:SSL:yaSSL, a different vulnerability than CVE-2014-6500.
Published 2014-10-15 · Modified
7.5EPSS 0.057
CVE-2017-10624
Junos Space: Insufficient verification of node certificates.
Published 2017-10-13 · Modified
7.5EPSS 0.004
CVE-2025-59976
Junos Space: Arbitrary file download vulnerability in web interface
Published 2025-10-09 · Analyzed
7.1EPSS 0.003
CVE-2018-0013
Junos Space: Local File Inclusion Vulnerability
Published 2018-01-10 · Modified
6.5EPSS 0.012
CVE-2017-2308
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.
Published 2017-05-30 · Modified
6.5EPSS 0.012
CVE-2016-4931
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
Published 2017-03-20 · Modified
6.5EPSS 0.009
CVE-2016-4930
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
Published 2017-03-20 · Modified
6.1EPSS 0.009
CVE-2017-2307
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
Published 2017-05-30 · Modified
6.1EPSS 0.009
CVE-2025-59981
Junos Space: Device Template Definition page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.003
CVE-2025-59982
Junos Space: Dashboard Search field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.003
CVE-2025-59983
Junos Space: Template Definition page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.003
CVE-2025-59989
Junos Space: Device Discovery page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59999
Junos Space: API Access Profiles page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59988
Junos Space: Generate Report page is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59987
Junos Space: The arbitrary device search field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59991
Junos Space: Device Management pages are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59986
Junos Space: Input fields in Model Devices are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59985
Junos Space: Purging Policy field is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59984
Junos Space: Global Search is vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
CVE-2025-59993
Junos Space: Space Node Setting fields are vulnerable to reflected cross-site script injection
Published 2025-10-09 · Analyzed
6.1EPSS 0.002
1 / 2Next →