Skip to main content

Vendor/product archive

juniper / junos CVEs

Beta · best-effort

786 CVEs tagged to juniper / junos32 Critical, 419 High, 333 Medium, 2 Low, 0 Unrated.

CVE-2021-0293

Published Jul 15, 2021

A vulnerability in Juniper Networks Junos OS caused by Missing Release of Memory after Effective Lifetime leads to a memory leak each time the CLI command 'show system connections…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0287

Published Jul 15, 2021

In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0283

Published Jul 15, 2021

A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0282

Published Jul 15, 2021

On Juniper Networks Junos OS devices with Multipath or add-path feature enabled, processing a specific BGP UPDATE can lead to a routing process daemon (RPD) crash and restart, cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0281

Published Jul 15, 2021

On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0278

Published Jul 15, 2021

An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target devic…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0277

Published Jul 15, 2021

An Out-of-bounds Read vulnerability in the processing of specially crafted LLDP frames by the Layer 2 Control Protocol Daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0270

Published Apr 22, 2021

On PTX Series and QFX10k Series devices with the "inline-jflow" feature enabled, a use after free weakness in the Packet Forwarding Engine (PFE) microkernel architecture of Junipe…

CVSS 7.5 · High

CVE-2021-0269

Published Apr 22, 2021

The improper handling of client-side parameters in J-Web of Juniper Networks Junos OS allows an attacker to perform a number of different malicious actions against a target device…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0268

Published Apr 22, 2021

An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0267

Published Apr 22, 2021

An Improper Input Validation vulnerability in the active-lease query portion in JDHCPD's DHCP Relay Agent of Juniper Networks Junos OS allows an attacker to cause a Denial of Serv…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0266

Published Apr 22, 2021

The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks Junos OS allows an attacker to take control of any instance of a cSRX deployment thro…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0264

Published Apr 22, 2021

A vulnerability in the processing of traffic matching a firewall filter containing a syslog action in Juniper Networks Junos OS on MX Series with MPC10/MPC11 cards installed, PTX1…

CVSS 5.9 · Medium
Showing 401-425 of 786 CVEsPage 17 of 32