Juniper Junos Space vulnerabilities
78 known vulnerabilities affecting juniper/junos_space.
Total CVEs
78
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH15MEDIUM53
Vulnerabilities
Page 4 of 4
CVE-2025-59986P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59986 [MEDIUM] CWE-79 CVE-2025-59986: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the input fields in Model Devices that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This
nvd
CVE-2017-2310P4MEDIUMCVSS 5.3≤ 15.22017-05-30
CVE-2017-2310 [MEDIUM] CVE-2017-2310: A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions
A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.
nvd
CVE-2018-0046P4MEDIUMCVSS 6.1v18.1r12018-10-10
CVE-2018-0046 [MEDIUM] CWE-79 CVE-2018-0046: A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space
A reflected cross-site scripting vulnerability in OpenNMS included with Juniper Networks Junos Space may allow the stealing of sensitive information or session credentials from Junos Space administrators or perform administrative actions. This issue affects Juniper Networks Junos Space versions prior to 18.2R1.
nvd
CVE-2015-2620P4MEDIUMCVSS 4.3≤ 15.12015-07-16
CVE-2015-2620 [MEDIUM] CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2025-59984P4MEDIUMCVSS 6.1fixed in 24.1v24.12025-10-09
CVE-2025-59984 [MEDIUM] CWE-79 CVE-2025-59984: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in Global Search that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.This issue affects all ve
nvd
CVE-2014-6559P4MEDIUMCVSS 4.3≤ 15.12014-10-15
CVE-2014-6559 [MEDIUM] CVE-2014-6559: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
nvd
CVE-2014-6494P4MEDIUMCVSS 4.3≤ 15.12014-10-15
CVE-2014-6494 [MEDIUM] CVE-2014-6494: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
nvd
CVE-2018-0047P4MEDIUMCVSS 5.4v13.3v14.1+5 more2018-10-10
CVE-2018-0047 [MEDIUM] CWE-79 CVE-2018-0047: A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Dir
A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user when other users access the Security Director web interface. This issue affects all versions
nvd
CVE-2014-6496P4MEDIUMCVSS 4.3≤ 15.12014-10-15
CVE-2014-6496 [MEDIUM] CVE-2014-6496: Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
nvd
CVE-2017-2307P4MEDIUMCVSS 6.1≤ 15.22017-05-30
CVE-2017-2307 [MEDIUM] CWE-79 CVE-2017-2307: A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks J
A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.
nvd
CVE-2016-4930P4MEDIUMCVSS 6.1≤ 15.22017-03-20
CVE-2016-4930 [MEDIUM] CWE-79 CVE-2016-4930: Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to ste
Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions.
nvd
CVE-2018-0011P4MEDIUMCVSS 5.4v13.3v14.1+4 more2018-01-10
CVE-2018-0011 [MEDIUM] CWE-79 CVE-2018-0011: A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote a
A reflected cross site scripting (XSS) vulnerability in Junos Space may potentially allow a remote authenticated user to inject web script or HTML and steal sensitive data and credentials from a session, and to perform administrative actions on the Junos Space network management device.
nvd
CVE-2014-6495P4MEDIUMCVSS 4.3≤ 15.12014-10-15
CVE-2014-6495 [MEDIUM] CVE-2014-6495: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
nvd
CVE-2014-6478P4MEDIUMCVSS 4.3≤ 15.12014-10-15
CVE-2014-6478 [MEDIUM] CVE-2014-6478: Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
nvd
CVE-2013-5096P4MEDIUMCVSS 4.0v11.1v11.2+5 more2013-08-16
CVE-2013-5096 [MEDIUM] CWE-264 CVE-2013-5096: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804.
nvd
CVE-2013-5095P4MEDIUMCVSS 4.3v11.1v11.2+5 more2013-08-16
CVE-2013-5095 [MEDIUM] CWE-79 CVE-2013-5095: Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka PR 884469.
nvd
CVE-2013-5097P4MEDIUMCVSS 4.0v11.1v11.2+5 more2013-08-16
CVE-2013-5097 [MEDIUM] CWE-264 CVE-2013-5097: Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462.
nvd
CVE-2013-3497P4MEDIUMCVSS 4.7≤ 12.3v1.0+11 more2013-05-08
CVE-2013-3497 [MEDIUM] CWE-255 CVE-2013-3497: Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes
Juniper Junos Space before 12.3P2.8, as used on the JA1500 appliance and in other contexts, includes a cleartext password in a configuration tab, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
nvd
← Previous4 / 4