Critical - CVE-2025-52950 - A Missing Authorization vulnerability in...
A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web...
Medium - CVE-2025-52951 - A Protection Mechanism Failure vulnerability in...
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic to an interface to effectively bypass any firewall...
Medium - CVE-2025-52952 - An Out-of-bounds Write vulnerability in the...
An Out-of-bounds Write vulnerability in the connectivity fault management (CFM) daemon of Juniper Networks Junos OS on MX Series with MPC-BUILTIN, MPC1 through MPC9 line cards allows an...
Medium - CVE-2025-52953 - An Expected Behavior Violation vulnerability in...
An Expected Behavior Violation vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker sending a valid BGP...
High - CVE-2025-52954 - A Missing Authorization vulnerability in the...
A Missing Authorization vulnerability in the internal virtual routing and forwarding (VRF) of Juniper Networks Junos OS Evolved allows a local, low-privileged user to gain root privileges, leading...
Medium - CVE-2025-52955 - An Incorrect Calculation of Buffer Size...
An Incorrect Calculation of Buffer Size vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a memory corruption that...
Medium - CVE-2025-52958 - A Reachable Assertion vulnerability in the...
A Reachable Assertion vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker to cause a Denial of Service...
Medium - CVE-2025-52963 - An Improper Access Control vulnerability in the...
An Improper Access Control vulnerability in the User Interface (UI) of Juniper Networks Junos OS allows a local, low-privileged attacker to bring down an interface, leading to a Denial-of-Service....
Medium - CVE-2025-52964 - A Reachable Assertion vulnerability in the...
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of...
NA - CVE-2025-52994 - gif_outputAsJpeg in phpThumb through 1.7.23...
gif_outputAsJpeg in phpThumb through 1.7.23 allows phpthumb.gif.php OS Command Injection via a crafted parameter value. This is fixed in 1.7.23-202506081709.