Vulnerabilities

Summary — last 7 days

New vulnerabilities2,759▲ 5 vs. last week
Critical / high1,275▼ 253 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)242▲ 224 vs. last week
–

12 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.8)2.0%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+910/14/20146/17/2026
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted…
ModifiedMedium (5.4)1.7%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20146/17/2026
Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4.
ModifiedHigh (7.8)3.4%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20146/17/2026
Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a…
ModifiedHigh (7.8)1.8%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20146/17/2026
Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
ModifiedHigh (7.1)2.3%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+91/15/20146/17/2026
Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.
ModifiedHigh (7.8)3.6%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+91/11/20146/17/2026
Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP…
ModifiedMedium (5)2.1%—Juniper JunosJuniper Srx1400Juniper Srx3400Juniper Srx36007/11/20136/16/2026
Juniper Junos 10.4 before 10.4S13, 11.4 before 11.4R7-S1, 12.1 before 12.1R5-S3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on the SRX1400, SRX3400, and SRX3600 does not properly initialize memory locations used during padding of Ethernet packets, which allows remote attackers to obtain sensitive…
ModifiedHigh (7.8)1.9%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20136/16/2026
flowd in Juniper Junos 10.4 before 10.4R11 on SRX devices, when the MSRPC Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted MSRPC requests, aka PR 772834.
ModifiedHigh (7.8)2.6%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20136/16/2026
flowd in Juniper Junos 10.4 before 10.4S14, 11.2 and 11.4 before 11.4R6-S2, and 12.1 before 12.1R6 on SRX devices, when certain Application Layer Gateways (ALGs) are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted TCP packets, aka PRs 727980, 806269, and 835593.
ModifiedHigh (10)7.6%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20136/16/2026
Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100.
ModifiedHigh (7.8)2.8%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+97/11/20136/16/2026
flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R8, 12.1 before 12.1R7, and 12.1X44 before 12.1X44-D15 on SRX devices, when PIM and NAT are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted PIM packets, aka PR 842253.
ModifiedHigh (7.8)3.3%—HP Bl860cHP Rx2660HP Rx3600HP Rx66004/8/20086/16/2026
Unspecified vulnerability in the embedded management console in HP iLO-2 Management Processors (iLO-2 MP), as used in Integrity Servers rx2660, rx3600, and rx6600, and Integrity Blade Server model bl860c, allows remote attackers to cause a denial of service via unknown vectors.
Orbitaley — Vulnerabilities