Vulnerabilities > Juniper

DATE CVE VULNERABILITY TITLE RISK
2017-04-24 CVE-2017-2320 Information Exposure vulnerability in Juniper Northstar Controller
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.
network
low complexity
juniper CWE-200
critical
10.0
2017-04-24 CVE-2017-2319 Improper Authentication vulnerability in Juniper Northstar Controller
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.
network
low complexity
juniper CWE-287
7.5
2017-04-24 CVE-2017-2318 Information Exposure vulnerability in Juniper Northstar Controller
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges.
network
low complexity
juniper CWE-200
4.0
2017-04-24 CVE-2017-2317 Information Exposure vulnerability in Juniper Northstar Controller
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.
network
low complexity
juniper CWE-200
7.5
2017-04-24 CVE-2017-2316 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Juniper Northstar Controller
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.
local
low complexity
juniper CWE-119
2.1
2017-04-24 CVE-2017-2315 Missing Release of Resource after Effective Lifetime vulnerability in Juniper Junos
On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause a slow memory leak.
network
low complexity
juniper CWE-772
7.8
2017-04-24 CVE-2017-2313 Improper Input Validation vulnerability in Juniper Junos
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart.
network
low complexity
juniper CWE-20
5.0
2017-04-24 CVE-2017-2312 Missing Release of Resource after Effective Lifetime vulnerability in Juniper Junos
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process.
network
low complexity
juniper CWE-772
6.8
2017-03-20 CVE-2016-4931 XXE vulnerability in Juniper Junos Space 15.1/15.2
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
network
low complexity
juniper CWE-611
4.0
2017-03-20 CVE-2016-4930 Cross-site Scripting vulnerability in Juniper Junos Space 15.1/15.2
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
network
juniper CWE-79
4.3