juniper kayıtları
juniper üreticisine ait 1.112 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 8 · %0,7
- Silahlaştırılmış
- 11 · %1
- Pre-auth RCE
- 41
- Düzeltme kaydı olan
- %33,5
- Yayından KEV’e ortanca
- 88 gün
Tekrar eden sınıflar
- CWE-20 Improper Input Validation93
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')80
- CWE-754 Improper Check for Unusual or Exceptional Conditions68
- CWE-400 Uncontrolled Resource Consumption51
- CWE-401 Missing Release of Memory after Effective Lifetime39
- CWE-755 Improper Handling of Exceptional Conditions36
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
1.112 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
98Hemen | CVE-2023-36845Silahlaştırılmış | Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variablejuniper · junos · CWE-473 | Kritik9,8 | KEV | %95,1 | 17 Ağu 2023 |
87Hemen | CVE-2015-7755Silahlaştırılmış | Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 beforejuniper · screenos · CWE-287 | Kritik9,8 | KEV | %61,1 | 19 Ara 2015 |
79Bu hafta | CVE-2023-36846Silahlaştırılmış | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Orta5,3 | KEV | %93,5 | 17 Ağu 2023 |
78Bu hafta | CVE-2023-36844Silahlaştırılmış | Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variablesjuniper · junos · CWE-473 | Orta5,3 | KEV | %90,0 | 17 Ağu 2023 |
76Bu hafta | CVE-2023-36847Silahlaştırılmış | Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary filesjuniper · junos · CWE-306 | Orta5,3 | KEV | %83,5 | 17 Ağu 2023 |
70Bu hafta | CVE-2020-1631Silahlaştırılmış | Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) servicesjuniper · junos · CWE-22 | Kritik9,8 | KEV | %4,8 | 4 May 2020 |
69Bu hafta | CVE-2022-42889Silahlaştırılmış | Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaultsapache · commons text · CWE-94 | Kritik9,8 | — | %99,9 | 13 Eki 2022 |
61Bu hafta | CVE-2020-10188İstismar yok | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becausnetkit telnet project · netkit telnet · CWE-120 | Kritik9,8 | — | %74,3 | 6 Mar 2020 |
61Bu hafta | CVE-2008-0960Kavram kanıtı | SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Jnet-snmp · net snmp · CWE-287 | Kritik10,0 | — | %68,8 | 10 Haz 2008 |
57Planlayın | CVE-2025-21590Silahlaştırılmış | Junos OS: An local attacker with shell access can execute arbitrary codejuniper · junos · CWE-653 | Orta6,7 | KEV | %1,7 | 12 Mar 2025 |
53Planlayın | CVE-2016-1286İstismar yok | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure anisc · bind | Yüksek8,6 | — | %62,1 | 9 Mar 2016 |
52Planlayın | CVE-2009-1185Silahlaştırılmış | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senudev project · udev · CWE-346 | Yüksek7,2 | — | %80,4 | 17 Nis 2009 |
51Planlayın | CVE-2023-36851Silahlaştırılmış | Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary filesjuniper · junos · CWE-306 | Orta5,3 | KEV | %1,1 | 27 Eyl 2023 |
50Planlayın | CVE-2019-11358Kavram kanıtı | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Orta6,1 | — | %87,2 | 19 Nis 2019 |
50Planlayın | CVE-2006-2086Silahlaştırılmış | Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE dejuniper · junipersetup control | Yüksek7,5 | — | %67,3 | 29 Nis 2006 |
45Planlayın | CVE-2016-1285İstismar yok | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, isc · bind | Orta6,8 | — | %59,1 | 9 Mar 2016 |
44Planlayın | CVE-2004-0230Kavram kanıtı | TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectiojuniper · junos | Orta5,0 | — | %80,3 | 18 Ağu 2004 |
44Planlayın | CVE-2024-21591İstismar yok | Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Executionjuniper · junos · CWE-787 | Kritik9,8 | — | %17,5 | 11 Oca 2024 |
42Planlayın | CVE-2026-21902Kavram kanıtı | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Kritik9,3 | — | %18,0 | 25 Şub 2026 |
42Planlayın | CVE-2013-4685İstismar yok | Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRXjuniper · junos · CWE-119 | Kritik10,0 | — | %7,6 | 11 Tem 2013 |
42Planlayın | CVE-2014-0429İstismar yok | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote oracle · jrockit | Kritik10,0 | — | %7,3 | 15 Nis 2014 |
42Planlayın | CVE-2014-0456İstismar yok | Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,oracle · jrockit | Kritik10,0 | — | %6,6 | 15 Nis 2014 |
42Planlayın | CVE-2014-2421İstismar yok | Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to aoracle · jrockit | Kritik10,0 | — | %6,6 | 15 Nis 2014 |
42Planlayın | CVE-2014-0457İstismar yok | Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remooracle · jrockit | Kritik10,0 | — | %6,6 | 15 Nis 2014 |
41Planlayın | CVE-2018-0001İstismar yok | Junos: Unauthenticated Remote Code Execution through J-Web interfacejuniper · junos · CWE-416 | Kritik9,8 | — | %6,3 | 10 Oca 2018 |
- CVE-2023-3684598Hemen
Junos OS: EX and SRX Series: A PHP vulnerability in J-Web allows an unauthenticated to control an important environment variable
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95juniper · junos17 Ağu 2023
- CVE-2015-775587Hemen
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61juniper · screenos19 Ara 2015
- CVE-2023-3684679Bu hafta
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %93juniper · junos17 Ağu 2023
- CVE-2023-3684478Bu hafta
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %90juniper · junos17 Ağu 2023
- CVE-2023-3684776Bu hafta
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %83juniper · junos17 Ağu 2023
- CVE-2020-163170Bu hafta
Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %5juniper · junos4 May 2020
- CVE-2022-4288969Bu hafta
Apache Commons Text prior to 1.10.0 allows RCE when applied to untrusted input due to insecure interpolation defaults
KritikCVSS 9,8SilahlaştırılmışEPSS %100apache · commons text13 Eki 2022
- CVE-2020-1018861Bu hafta
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, becaus
KritikCVSS 9,8İstismar yokEPSS %74netkit telnet project · netkit telnet6 Mar 2020
- CVE-2008-096061Bu hafta
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) J
KritikCVSS 10,0Kavram kanıtıEPSS %69net-snmp · net snmp10 Haz 2008
- CVE-2025-2159057Planlayın
Junos OS: An local attacker with shell access can execute arbitrary code
OrtaCVSS 6,7KEVSilahlaştırılmışEPSS %2juniper · junos12 Mar 2025
- CVE-2016-128653Planlayın
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure an
YüksekCVSS 8,6İstismar yokEPSS %62isc · bind9 Mar 2016
- CVE-2009-118552Planlayın
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sen
YüksekCVSS 7,2SilahlaştırılmışEPSS %80udev project · udev17 Nis 2009
- CVE-2023-3685151Planlayın
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
OrtaCVSS 5,3KEVSilahlaştırılmışEPSS %1juniper · junos27 Eyl 2023
- CVE-2019-1135850Planlayın
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
OrtaCVSS 6,1Kavram kanıtıEPSS %87jquery · jquery19 Nis 2019
- CVE-2006-208650Planlayın
Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE de
YüksekCVSS 7,5SilahlaştırılmışEPSS %67juniper · junipersetup control29 Nis 2006
- CVE-2016-128545Planlayın
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages,
OrtaCVSS 6,8İstismar yokEPSS %59isc · bind9 Mar 2016
- CVE-2004-023044Planlayın
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connectio
OrtaCVSS 5,0Kavram kanıtıEPSS %80juniper · junos18 Ağu 2004
- CVE-2024-2159144Planlayın
Junos OS: SRX Series and EX Series: Security Vulnerability in J-web allows a preAuth Remote Code Execution
KritikCVSS 9,8İstismar yokEPSS %18juniper · junos11 Oca 2024
- CVE-2026-2190242Planlayın
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
KritikCVSS 9,3Kavram kanıtıEPSS %18juniper · junos os evolved25 Şub 2026
- CVE-2013-468542Planlayın
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX
KritikCVSS 10,0İstismar yokEPSS %8juniper · junos11 Tem 2013
- CVE-2014-042942Planlayın
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote
KritikCVSS 10,0İstismar yokEPSS %7oracle · jrockit15 Nis 2014
- CVE-2014-045642Planlayın
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality,
KritikCVSS 10,0İstismar yokEPSS %7oracle · jrockit15 Nis 2014
- CVE-2014-242142Planlayın
Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to a
KritikCVSS 10,0İstismar yokEPSS %7oracle · jrockit15 Nis 2014
- CVE-2014-045742Planlayın
Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remo
KritikCVSS 10,0İstismar yokEPSS %7oracle · jrockit15 Nis 2014
- CVE-2018-000141Planlayın
Junos: Unauthenticated Remote Code Execution through J-Web interface
KritikCVSS 9,8İstismar yokEPSS %6juniper · junos10 Oca 2018