← Back

Juniper

juniper

1,105 CVEs • 432 products

Products (432)

Click to collapse
Toggle
Junos
junos
Junos Space
junos_space
Screenos
screenos
Srx100
srx100
Srx110
srx110
Srx1400
srx1400
Srx210
srx210
Srx220
srx220
Srx240
srx240
Srx3400
srx3400
Srx3600
srx3600
Srx550
srx550
Srx650
srx650
Srx5600
srx5600
Srx5800
srx5800
Ive Os
ive_os
Libslax
libslax
Junose
junose
Ctpview
ctpview
Mist Cloud Ui
mist_cloud_ui
Junos E
junos_e
Secure Access
secure_access
Smartpass
smartpass
Contrail
contrail
Appformix
appformix
Netscreen 5gt
netscreen-5gt
Netscreen Idp
netscreen-idp
Junos J
junos_j
Junos M
junos_m
Junos T
junos_t
Junose E
junose_e
Junose J
junose_j
Junose M
junose_m
Junose T
junose_t
Dx
dx
Http Service
http_service
Src Pe
src_pe
Jnos
jnos
Idp
idp
Idp250
idp250
Idp75
idp75
Idp800
idp800
Idp8200
idp8200
Nsm3000
nsm3000
Nsmexpress
nsmexpress
Ringmaster
ringmaster

CVEs (1,105)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underly...Show more
An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of servi...Show more
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker crafting packets destined to the device to cause a persistent de...Show more
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker crafting packets destined to the device to cause a persistent denial of service to the path computation server service.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to fu...Show more
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading t...Show more
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
8.3 HIGH· v3
7.5 HIGH· v2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, lea...Show more
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or...Show more
A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services...Show more
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.Show less
1Juniper
1Northstar Controller
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of servi...Show more
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.Show less
1Juniper
1Junos
May 13, 2026
Apr 24, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined t...Show more
On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause a slow memory leak. A malicious network-based packet flood of these crafted IPv6 NDP packets may eventually lead to resource exhaustion and a denial of service. The affected Junos OS versions are: 12.3 prior to 12.3R12-S4, 12.3R13; 13.3 prior to 13.3R10; 14.1 prior to 14.1R8-S3, 14.1R9; 14.1X53 prior ro 14.1X53-D12, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R6-S4, 14.2R7-S6, 14.2R8; 15.1 prior to 15.1R5; 16.1 before 16.1R3; 16.2 before 16.2R1-S3, 16.2R2. 17.1R1 and all subsequent releases have a resolution for this vulnerability.Show less
1Juniper
1Junos
May 13, 2026
Apr 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart. Repeated crashes of the rpd daemon c...Show more
Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition. The affected Junos OS versions are: 15.1 prior to 15.1F2-S15, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D78, 15.1X49-D80; 15.1X53 prior to 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 prior to 16.1R3-S3, 16.1R4; 16.2 prior to 16.2R1-S3, 16.2R2; Releases prior to Junos OS 15.1 are unaffected by this vulnerability. 17.1R1, 17.2R1, and all subsequent releases have a resolution for this vulnerability.Show less
1Juniper
1Junos
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing prot...Show more
On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process. Over time, repeatedly receiving this type of LDP packet(s) will cause the memory to exhaust and the rpd process to crash and restart. It is not possible to free up the memory that has been consumed without restarting the rpd process. This issue affects Junos OS based devices with either IPv4 or IPv6 LDP enabled via the [protocols ldp] configuration (the native IPv6 support for LDP is available in Junos OS 16.1 and higher). The interface on which the packet arrives needs to have LDP enabled. The affected Junos versions are: 13.3 prior to 13.3R10; 14.1 prior to 14.1R8; 14.2 prior to 14.2R7-S6 or 14.2R8; 15.1 prior to 15.1F2-S14, 15.1F6-S4, 15.1F7, 15.1R4-S7, 15.1R5; 15.1X49 before 15.1X49-D70; 15.1X53 before 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 before 16.1R2. 16.2R1 and all subsequent releases have a resolution for this vulnerability.Show less
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Insufficient validation of SSH keys in Junos Space before 15.2R2 allows man-in-the-middle (MITM) type of attacks while a Space device is communicating with managed devices.
1Juniper
1Junos Space
May 13, 2026
Mar 20, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.
7Debian
FedoraprojectJqueryui+4 more
13Application Express
Business IntelligenceDebian Linux+10 more
May 13, 2026
Mar 15, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.