CVEs (589)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 31, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the primary flow, the initial flow will remain after the closing procedure...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 31, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to inte...Show more |
1F5 3Big Ip Access Policy Manager Big Ip Access Policy Manager ClientBig Ip Edge ClientNov 21, 2024 Oct 19, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, there is a reflected Cross Site Scripting (XSS) vulnerability in an undisclosed Configuration Utility page. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 19, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On F5 BIG-IP 13.0.0-13.1.1.1 and 12.1.0-12.1.3.6, a reflected Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an authenticated user to execute JavaSc...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Oct 10, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.5.1-11.5.6 is processing specially crafted TCP traffic with the Large Receive Offload (LRO) feature enabled, TMM may crash, leading to a failover ev...Show more |
1F5 8Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+5 moreNov 21, 2024 Oct 8, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkernel (TMM) may not properly clean-up pool member network connections when using SPDY or HTTP/2 virtual...Show more |
6Canonical F5Linux+3 more28Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+25 moreJan 27, 2026 Sep 25, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on t...Show more |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Sep 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 On BIG-IP APM 11.6.0-11.6.3.1, 12.1.0-12.1.3.3, 13.0.0, and 13.1.0-13.1.0.3, APMD may core when processing SAML Assertion or response containing certain elements. |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Sep 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect UR...Show more |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Sep 13, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages. |
7Canonical DebianF5+4 more51Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+48 moreNov 21, 2024 Sep 6, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending...Show more |
1F5 2Big Ip Access Policy Manager Big Ip Access Policy Manager ClientNov 21, 2024 Aug 17, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process and can allow an unprivileged user to get ownership of files owned by root on the...Show more |
8A10networks CanonicalCisco+5 more38Advanced Core Operating System Aruba Airwave AmpAruba Clearpass Policy Manager+35 moreNov 21, 2024 Aug 6, 2018 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service. |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Jul 31, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When the F5 BIG-IP APM 13.0.0-13.1.1 or 12.1.0-12.1.3 renders certain pages (pages with a logon agent or a confirm box), the BIG-IP APM may disclose configuration information such as partition and agent names via URI par...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Jul 25, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server. |
1F5 10Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+7 moreNov 21, 2024 Jul 25, 2018 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart...Show more |
1F5 1Big Ip Access Policy Manager Nov 21, 2024 Jul 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM mo...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreNov 21, 2024 Jul 25, 2018 N/A· v4 7.4 HIGH· v3 6.1 MEDIUM· v2 Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sour...Show more |
1F5 9Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+6 moreNov 21, 2024 Jul 25, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb". |