Vulnerabilities > Juniper

DATE CVE VULNERABILITY TITLE RISK
2018-10-10 CVE-2018-0048 Resource Exhaustion vulnerability in Juniper Junos
A vulnerability in the Routing Protocols Daemon (RPD) with Juniper Extension Toolkit (JET) support can allow a network based unauthenticated attacker to cause a severe memory exhaustion condition on the device.
network
low complexity
juniper CWE-400
5.0
2018-10-10 CVE-2018-0047 Cross-site Scripting vulnerability in Juniper Junos Space
A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts.
network
juniper CWE-79
3.5
2018-10-10 CVE-2018-0046 Cross-site Scripting vulnerability in Juniper Junos Space 18.1R1
A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions.
network
juniper CWE-79
4.3
2018-10-10 CVE-2018-0045 Improper Input Validation vulnerability in Juniper Junos
Receipt of a specific Draft-Rosen MVPN control packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution.
low complexity
juniper CWE-20
5.8
2018-10-10 CVE-2018-0044 Improper Authentication vulnerability in Juniper Junos
An insecure SSHD configuration in Juniper Device Manager (JDM) and host OS on Juniper NFX Series devices may allow remote unauthenticated access if any of the passwords on the system are empty.
network
juniper CWE-287
6.8
2018-10-10 CVE-2018-0043 Improper Input Validation vulnerability in Juniper Junos
Receipt of a specific MPLS packet may cause the routing protocol daemon (RPD) process to crash and restart or may lead to remote code execution.
low complexity
juniper CWE-20
5.8
2018-08-18 CVE-2018-15505 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
network
low complexity
embedthis juniper CWE-476
7.5
2018-08-18 CVE-2018-15504 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2.
network
low complexity
embedthis juniper CWE-476
7.5
2018-07-11 CVE-2018-0042 Information Exposure Through Log Files vulnerability in Juniper Contrail Service Orchestration
Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.
network
low complexity
juniper CWE-532
5.0
2018-07-11 CVE-2018-0041 Use of Hard-coded Credentials vulnerability in Juniper Contrail Service Orchestration
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service.
network
low complexity
juniper CWE-798
7.5