imPC@ndo EN

Vulnerabilità F5

1037 CVE

CVE-2011-4963
Media 5.0

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences in a request.

f5 nginx
0.06EPSS
CVE-2007-6704
Bassa 2.6

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activa…

f5 firepass_4100
0.06EPSS
CVE-2011-3188
Critica 9.1

The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking…

f5 arx · f5 big-ip_access_policy_manager · f5 big-ip_analytics · f5 big-ip_application_security_manager · e altri 11
0.06EPSS
CVE-2014-3616
Media 4.3

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host conf…

debian debian_linux · f5 nginx
0.06EPSS
CVE-2018-16890
Alta 7.5

libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an in…

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · haxx libcurl · e altri 6
0.05EPSS
CVE-2021-23024
Alta 7.2

On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated remote command execution vulnerability in undisclosed pages. Note: Software versions which have reached End of Technical Support (EoTS) are not…

f5 big-iq_centralized_management
0.05EPSS
CVE-2018-14880
Alta 7.5

The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

apple mac_os_x · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 19
0.05EPSS
CVE-2018-14469
Alta 7.5

The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · e altri 3
0.05EPSS
CVE-2018-20836
Alta 8.1

An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free.

canonical ubuntu_linux · debian debian_linux · f5 traffix_signaling_delivery_controller · linux linux_kernel · e altri 9
0.05EPSS
CVE-2012-3163
Alta 9.0

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 17
0.05EPSS
CVE-2019-13565
Alta 7.5

An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for…

apple mac_os_x · canonical ubuntu_linux · debian debian_linux · f5 traffix_signaling_delivery_controller · e altri 5
0.05EPSS
CVE-2019-10744
Critica 9.1

Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · e altri 17
0.05EPSS
CVE-2016-1247
Alta 7.8

The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on…

f5 nginx · fedoraproject fedora
0.05EPSS
CVE-2016-5745
Critica 9.8

F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or …

f5 big-ip_local_traffic_manager
0.05EPSS
CVE-2018-14463
Alta 7.5

The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167.

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · e altri 3
0.05EPSS
CVE-2015-8098
Critica 9.8

F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors related to processing a Citrix Remote Desktop connection through a …

f5 big-ip_access_policy_manager
0.05EPSS
CVE-2018-14879
Alta 7.0

The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · e altri 3
0.05EPSS
CVE-2016-7472
Alta 7.5

F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.

f5 big-ip_application_security_manager
0.04EPSS
CVE-2018-5504
Alta 8.1

In some circumstances, the Traffic Management Microkernel (TMM) does not properly handle certain malformed Websockets requests/responses, which allows remote attackers to cause a denial-of-service (DoS) or possible remote code execution on the F5 BIG-IP system…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · e altri 9
0.04EPSS
CVE-2018-14465
Alta 7.5

The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

apple mac_os_x · debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · e altri 3
0.04EPSS
CVE-2024-3661
Alta 7.6

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network c…

cisco anyconnect_vpn_client · cisco secure_client · citrix secure_access_client · f5 big-ip_access_policy_manager · e altri 5
0.04EPSS
CVE-2018-20657
Alta 7.5

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.

f5 traffix_signaling_delivery_controller · gnu binutils
0.04EPSS
CVE-2026-42055
Alta 8.1

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_head…

f5 dos · f5 nginx_gateway_fabric · f5 nginx_ingress_controller · f5 nginx_instance_manager · e altri 7
0.04EPSS
CVE-2017-6157
Alta 8.1

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 12.0.0 to 12.1.1, 11.6.0 to 11.6.1, 11.5.0 - 11.5.4, virtual servers with a configuration using the HTTP Explicit Proxy functionality and/or SOCKS prof…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_application_acceleration_manager · f5 big-ip_application_security_manager · e altri 4
0.04EPSS
CVE-2011-4968
Media 4.8

nginx http proxy module does not verify peer identity of https origin server which could facilitate man-in-the-middle attack (MITM)

debian debian_linux · f5 nginx
0.04EPSS