Записи Juniper
1 112 опубликованных записей вендора juniper.
Профиль для исследователя
- Попали в KEV
- 8 · 0,7 %
- С эксплойтом
- 11 · 1 %
- Pre-auth RCE
- 41
- С записью об исправлении
- 33,5 %
- Медиана: публикация → KEV
- 88 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation93
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')80
- CWE-754 Improper Check for Unusual or Exceptional Conditions68
- CWE-400 Uncontrolled Resource Consumption51
- CWE-401 Missing Release of Memory after Effective Lifetime39
- CWE-755 Improper Handling of Exceptional Conditions36
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 112 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
98Срочно | CVE-2023-36845Готовый эксплойт | Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variablejuniper · junos · CWE-473 | Критическая9,8 | KEV | 95,1 % | 17 авг. 2023 г. |
87Срочно | CVE-2015-7755Готовый эксплойт | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforejuniper · screenos · CWE-287 | Критическая9,8 | KEV | 61,1 % | 19 дек. 2015 г. |
79На этой неделе | CVE-2023-36846Готовый эксплойт | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Средняя5,3 | KEV | 93,5 % | 17 авг. 2023 г. |
78На этой неделе | CVE-2023-36844Готовый эксплойт | Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variablesjuniper · junos · CWE-473 | Средняя5,3 | KEV | 90,0 % | 17 авг. 2023 г. |
76На этой неделе | CVE-2023-36847Готовый эксплойт | Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Средняя5,3 | KEV | 83,5 % | 17 авг. 2023 г. |
70На этой неделе | CVE-2020-1631Готовый эксплойт | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) servicesjuniper · junos · CWE-22 | Критическая9,8 | KEV | 4,8 % | 4 мая 2020 г. |
69На этой неделе | CVE-2022-42889Готовый эксплойт | Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaultsapache · commons text · CWE-94 | Критическая9,8 | — | 99,9 % | 13 окт. 2022 г. |
61На этой неделе | CVE-2020-10188Эксплойта нет | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Критическая9,8 | — | 74,3 % | 6 мар. 2020 г. |
61На этой неделе | CVE-2008-0960Proof of concept | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Критическая10,0 | — | 68,8 % | 10 июн. 2008 г. |
57В плане | CVE-2025-21590Готовый эксплойт | Junos OS: An local attacker with shell access can execute arbitrary codejuniper · junos · CWE-653 | Средняя6,7 | KEV | 1,7 % | 12 мар. 2025 г. |
53В плане | CVE-2016-1286Эксплойта нет | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | Высокая8,6 | — | 62,1 % | 9 мар. 2016 г. |
52В плане | CVE-2009-1185Готовый эксплойт | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | Высокая7,2 | — | 80,4 % | 17 апр. 2009 г. |
51В плане | CVE-2023-36851Готовый эксплойт | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesjuniper · junos · CWE-306 | Средняя5,3 | KEV | 1,1 % | 27 сент. 2023 г. |
50В плане | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Средняя6,1 | — | 87,2 % | 19 апр. 2019 г. |
50В плане | CVE-2006-2086Готовый эксплойт | Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE dejuniper · junipersetup control | Высокая7,5 | — | 67,3 % | 29 апр. 2006 г. |
45В плане | CVE-2016-1285Эксплойта нет | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Средняя6,8 | — | 59,1 % | 9 мар. 2016 г. |
44В плане | CVE-2004-0230Proof of concept | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectiojuniper · junos | Средняя5,0 | — | 80,3 % | 18 авг. 2004 г. |
44В плане | CVE-2024-21591Эксплойта нет | Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Executionjuniper · junos · CWE-787 | Критическая9,8 | — | 17,5 % | 11 янв. 2024 г. |
42В плане | CVE-2026-21902Proof of concept | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Критическая9,3 | — | 18,0 % | 25 февр. 2026 г. |
42В плане | CVE-2013-4685Эксплойта нет | Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRXjuniper · junos · CWE-119 | Критическая10,0 | — | 7,6 % | 11 июл. 2013 г. |
42В плане | CVE-2014-0429Эксплойта нет | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote oracle · jrockit | Критическая10,0 | — | 7,3 % | 15 апр. 2014 г. |
42В плане | CVE-2014-0456Эксплойта нет | Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,oracle · jrockit | Критическая10,0 | — | 6,6 % | 15 апр. 2014 г. |
42В плане | CVE-2014-2421Эксплойта нет | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to aoracle · jrockit | Критическая10,0 | — | 6,6 % | 15 апр. 2014 г. |
42В плане | CVE-2014-0457Эксплойта нет | Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remooracle · jrockit | Критическая10,0 | — | 6,6 % | 15 апр. 2014 г. |
41В плане | CVE-2018-0001Эксплойта нет | Junos: Unauthenticated Remote Code Execution through J-Web interfacejuniper · junos · CWE-416 | Критическая9,8 | — | 6,3 % | 10 янв. 2018 г. |
- CVE-2023-3684598Срочно
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %juniper · junos17 авг. 2023 г.
- CVE-2015-775587Срочно
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %juniper · screenos19 дек. 2015 г.
- CVE-2023-3684679На этой неделе
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 93 %juniper · junos17 авг. 2023 г.
- CVE-2023-3684478На этой неделе
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 90 %juniper · junos17 авг. 2023 г.
- CVE-2023-3684776На этой неделе
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 83 %juniper · junos17 авг. 2023 г.
- CVE-2020-163170На этой неделе
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 5 %juniper · junos4 мая 2020 г.
- CVE-2022-4288969На этой неделе
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %apache · commons text13 окт. 2022 г.
- CVE-2020-1018861На этой неделе
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
КритическаяCVSS 9,8Эксплойта нетEPSS 74 %netkit telnet project · netkit telnet6 мар. 2020 г.
- CVE-2008-096061На этой неделе
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
КритическаяCVSS 10,0Proof of conceptEPSS 69 %net-snmp · net snmp10 июн. 2008 г.
- CVE-2025-2159057В плане
Junos OS: An local attacker with shell access can execute arbitrary code
СредняяCVSS 6,7KEVГотовый эксплойтEPSS 2 %juniper · junos12 мар. 2025 г.
- CVE-2016-128653В плане
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
ВысокаяCVSS 8,6Эксплойта нетEPSS 62 %isc · bind9 мар. 2016 г.
- CVE-2009-118552В плане
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
ВысокаяCVSS 7,2Готовый эксплойтEPSS 80 %udev project · udev17 апр. 2009 г.
- CVE-2023-3685151В плане
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
СредняяCVSS 5,3KEVГотовый эксплойтEPSS 1 %juniper · junos27 сент. 2023 г.
- CVE-2019-1135850В плане
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
СредняяCVSS 6,1Proof of conceptEPSS 87 %jquery · jquery19 апр. 2019 г.
- CVE-2006-208650В плане
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE de
ВысокаяCVSS 7,5Готовый эксплойтEPSS 67 %juniper · junipersetup control29 апр. 2006 г.
- CVE-2016-128545В плане
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
СредняяCVSS 6,8Эксплойта нетEPSS 59 %isc · bind9 мар. 2016 г.
- CVE-2004-023044В плане
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio
СредняяCVSS 5,0Proof of conceptEPSS 80 %juniper · junos18 авг. 2004 г.
- CVE-2024-2159144В плане
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %juniper · junos11 янв. 2024 г.
- CVE-2026-2190242В плане
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
КритическаяCVSS 9,3Proof of conceptEPSS 18 %juniper · junos os evolved25 февр. 2026 г.
- CVE-2013-468542В плане
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %juniper · junos11 июл. 2013 г.
- CVE-2014-042942В плане
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %oracle · jrockit15 апр. 2014 г.
- CVE-2014-045642В плане
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %oracle · jrockit15 апр. 2014 г.
- CVE-2014-242142В плане
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to a
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %oracle · jrockit15 апр. 2014 г.
- CVE-2014-045742В плане
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remo
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %oracle · jrockit15 апр. 2014 г.
- CVE-2018-000141В плане
Junos: Unauthenticated Remote Code Execution through J-Web interface
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %juniper · junos10 янв. 2018 г.