imPC@ndo IT

F5 vulnerabilities

1037 CVE

CVE-2011-4963
Medium 5.0

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.

f5 nginx
0.06EPSS
CVE-2007-6704
Low 2.6

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activa…

f5 firepass_4100
0.06EPSS
CVE-2011-3188
Critical 9.1

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking…

f5 arx · f5 big-ip_access_policy_manager · f5 big-ip_analytics · f5 big-ip_application_security_manager · and 11 more
0.06EPSS
CVE-2014-3616
Medium 4.3

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host conf…

debian debian_linux · f5 nginx
0.06EPSS
CVE-2018-16890
High 7.5

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an in…

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · haxx libcurl · and 6 more
0.05EPSS
CVE-2021-23024
High 7.2

On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not…

f5 big-iq_centralized_management
0.05EPSS
CVE-2018-14880
High 7.5

The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

apple mac_os_x · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · and 19 more
0.05EPSS
CVE-2018-14469
High 7.5

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · and 3 more
0.05EPSS
CVE-2018-20836
High 8.1

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

canonical ubuntu_linux · debian debian_linux · f5 traffix_signaling_delivery_controller · linux linux_kernel · and 9 more
0.05EPSS
CVE-2012-3163
High 9.0

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · and 17 more
0.05EPSS
CVE-2019-13565
High 7.5

An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for…

apple mac_os_x · canonical ubuntu_linux · debian debian_linux · f5 traffix_signaling_delivery_controller · and 5 more
0.05EPSS
CVE-2019-10744
Critical 9.1

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 17 more
0.05EPSS
CVE-2016-1247
High 7.8

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on…

f5 nginx · fedoraproject fedora
0.05EPSS
CVE-2016-5745
Critical 9.8

F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or …

f5 big-ip_local_traffic_manager
0.05EPSS
CVE-2018-14463
High 7.5

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · and 3 more
0.05EPSS
CVE-2015-8098
Critical 9.8

F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors related to processing a Citrix Remote Desktop connection through a …

f5 big-ip_access_policy_manager
0.05EPSS
CVE-2018-14879
High 7.0

The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · and 3 more
0.05EPSS
CVE-2016-7472
High 7.5

F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.

f5 big-ip_application_security_manager
0.04EPSS
CVE-2018-5504
High 8.1

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 9 more
0.04EPSS
CVE-2018-14465
High 7.5

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · and 3 more
0.04EPSS
CVE-2024-3661
High 7.6

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network c…

cisco anyconnect_vpn_client · cisco secure_client · citrix secure_access_client · f5 big-ip_access_policy_manager · and 5 more
0.04EPSS
CVE-2018-20657
High 7.5

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.

f5 traffix_signaling_delivery_controller · gnu binutils
0.04EPSS
CVE-2026-42055
High 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_head…

f5 dos · f5 nginx_gateway_fabric · f5 nginx_ingress_controller · f5 nginx_instance_manager · and 7 more
0.04EPSS
CVE-2017-6157
High 8.1

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS prof…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_application_acceleration_manager · f5 big-ip_application_security_manager · and 4 more
0.04EPSS
CVE-2011-4968
Medium 4.8

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

debian debian_linux · f5 nginx
0.04EPSS