CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 14Arx Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+11 moreNov 21, 2024 Feb 21, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The HTTPS protocol, as used in unspecified web applications, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which makes it easier for man-in-the-middle attackers to obtain pl...Show more |
1F5 19Arx Big Ip Access Policy ManagerBig Ip Advanced Firewall Manager+16 moreMay 6, 2026 Oct 15, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and 11.2.1 before HF11 and Enterprise Manager 3.x before 3.1.1 HF2, when co...Show more |
1F5 3Big Ip Access Policy Manager Big Ip Edge GatewayFirepassApr 29, 2026 Feb 10, 2014 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The Edge Client components in F5 BIG-IP APM 10.x, 11.x, 12.x, 13.x, and 14.x, BIG-IP Edge Gateway 10.x and 11.x, and FirePass 7.0.0 allow attackers to obtain sensitive information from process memory via unspecified vect...Show more |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreApr 29, 2026 Aug 9, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other pro...Show more |
3F5 LinuxRedhat15Arx Big Ip Access Policy ManagerBig Ip Analytics+12 moreApr 29, 2026 May 24, 2012 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a...Show more |
The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program...Show more |
SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter. |
my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid username, which allows remote attackers to conf...Show more |
F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address"), which allows remote authenticated users...Show more |
F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-encoded directory traversal or same-direct...Show more |