Juniper Networks just released a security advisory
PSN-2010-01-623, which states that the JUNOS kernel will crash (i.e. core) when a specifically crafted TCP option is received on a listening TCP port. The packet cannot be filtered with JUNOS's firewall filter. A router receiving this specific TCP packet will crash and reboot. As one can imagine this is a serious vulnerability, as this can bring down a router with a single packet attack.
For more info, please have a look at this
blog post. Below is a video of the DoS attack on a JunOS based router.