CVE-2018-0022
- EPSS 1.35%
- Published 11.04.2018 19:29:00
- Last modified 21.11.2024 03:37:22
A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is platform depen...
CVE-2018-0003
- EPSS 0.22%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to...
CVE-2018-0004
- EPSS 0.29%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
A sustained sequence of different types of normal transit traffic can trigger a high CPU consumption denial of service condition in the Junos OS register and schedule software interrupt handler subsystem when a specific command is issued to the devic...
CVE-2018-0005
- EPSS 0.22%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or other unintended conditions. Affected releases are Juniper Networks Ju...
CVE-2018-0006
- EPSS 0.4%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
A high rate of VLAN authentication attempts sent from an adjacent host on the local broadcast domain can trigger high memory utilization by the BBE subscriber management daemon (bbe-smgd), and lead to a denial of service condition. The issue was caus...
- EPSS 0.44%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corr...
CVE-2018-0008
- EPSS 0.15%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
An unauthenticated root login may allow upon reboot when a commit script is used. A commit script allows a device administrator to execute certain instructions during commit, which is configured under the [system scripts commit] stanza. Certain commi...
CVE-2018-0009
- EPSS 0.18%
- Published 10.01.2018 22:29:01
- Last modified 21.11.2024 03:37:20
On Juniper Networks SRX series devices, firewall rules configured to match custom application UUIDs starting with zeros can match all TCP traffic. Due to this issue, traffic that should have been blocked by other rules is permitted to flow through th...
CVE-2018-0001
- EPSS 4.22%
- Published 10.01.2018 22:29:00
- Last modified 21.11.2024 03:37:19
A remote, unauthenticated attacker may be able to execute code by exploiting a use-after-free defect found in older versions of PHP through injection of crafted data via specific PHP URLs within the context of the J-Web process. Affected releases are...
CVE-2018-0002
- EPSS 1.84%
- Published 10.01.2018 22:29:00
- Last modified 21.11.2024 03:37:19
On SRX Series and MX Series devices with a Service PIC with any ALG enabled, a crafted TCP/IP response packet processed through the device results in memory corruption leading to a flowd daemon crash. Sustained crafted response packets lead to repeat...