Vulnerabilities > Juniper > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-10-10 CVE-2018-0046 Cross-site Scripting vulnerability in Juniper Junos Space 18.1R1
A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions.
network
low complexity
juniper CWE-79
6.1
2018-07-11 CVE-2018-0034 Improper Input Validation vulnerability in Juniper Junos
A Denial of Service vulnerability exists in the Juniper Networks Junos OS JDHCPD daemon which allows an attacker to core the JDHCPD daemon by sending a crafted IPv6 packet to the system.
network
high complexity
juniper CWE-20
5.9
2018-07-11 CVE-2018-0031 Resource Exhaustion vulnerability in Juniper Junos
Receipt of specially crafted UDP/IP packets over MPLS may be able to bypass a stateless firewall filter.
network
high complexity
juniper CWE-400
5.9
2018-07-11 CVE-2018-0029 Resource Exhaustion vulnerability in Juniper Junos
While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore).
low complexity
juniper CWE-400
6.5
2018-07-11 CVE-2018-0027 Improper Input Validation vulnerability in Juniper Junos 16.1
Receipt of a crafted or malformed RSVP PATH message may cause the routing protocol daemon (RPD) to hang or crash.
network
high complexity
juniper CWE-20
5.9
2018-04-11 CVE-2018-0023 Incorrect Default Permissions vulnerability in Juniper Jsnapy
JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github.
local
low complexity
juniper CWE-276
5.5
2018-04-11 CVE-2018-0019 Improper Input Validation vulnerability in Juniper Junos
A vulnerability in Junos OS SNMP MIB-II subagent daemon (mib2d) may allow a remote network based attacker to cause the mib2d process to crash resulting in a denial of service condition (DoS) for the SNMP subsystem.
network
high complexity
juniper CWE-20
5.9
2018-04-11 CVE-2018-0018 Information Exposure vulnerability in Juniper Junos 12.1X46/12.3X48/15.1X49
On SRX Series devices during compilation of IDP policies, an attacker sending specially crafted packets may be able to bypass firewall rules, leading to information disclosure which an attacker may use to gain control of the target device or other internal devices, systems or services protected by the SRX Series device.
network
high complexity
juniper CWE-200
5.9
2018-04-11 CVE-2018-0017 Improper Input Validation vulnerability in Juniper Junos
A vulnerability in the Network Address Translation - Protocol Translation (NAT-PT) feature of Junos OS on SRX series devices may allow a certain valid IPv6 packet to crash the flowd daemon.
network
low complexity
juniper CWE-20
6.5
2018-01-10 CVE-2018-0014 Information Exposure vulnerability in Juniper Screenos
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets.
low complexity
juniper CWE-200
6.5