F5
f5
1,032 CVEs • 284 products
Products (284)
Click to collapseToggle
Products (284)
Click to collapse
CVEs (1,032)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML fil...Show more |
3F5 OpensuseSuse5Lifecycle Management Server NginxOpensuse+2 moreApr 29, 2026 Nov 23, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI. |
The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain sensitive information by reading the fil...Show more |
1F5 9Big Ip Access Policy Manager Big Ip Application Security ManagerBig Ip Edge Gateway+6 moreApr 29, 2026 Oct 26, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics 11.0.0; PSM 9.4.0 through 9.4.8, 10.0.0 through 10.2.4, and 11....Show more |
Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to inject arbitrary web script or HTML via t...Show more |
The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreApr 29, 2026 Aug 9, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other pro...Show more |
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sens...Show more |
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request wi...Show more |
6Canonical DebianF5+3 more21Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+18 moreApr 29, 2026 Oct 17, 2012 N/A· v4 N/A· v3 9.0 HIGH· v2 Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vec...Show more |
1F5 1Application Security Manager Appliance Apr 29, 2026 Sep 11, 2012 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or HTML via crafted requests that are later l...Show more |
nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2) certain "$index_allocation" sequences i...Show more |
1F5 25Big Ip 1000 Big Ip 11000Big Ip 11050+22 moreApr 29, 2026 Jul 9, 2012 N/A· v4 N/A· v3 7.8 HIGH· v2 F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a si...Show more |
3F5 LinuxRedhat15Arx Big Ip Access Policy ManagerBig Ip Analytics+12 moreApr 29, 2026 May 24, 2012 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a...Show more |
Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (mem...Show more |
3Debian F5Fedoraproject3Debian Linux FedoraNginxApr 29, 2026 Apr 17, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client requ...Show more |
The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local users to gain privileges via the sudo program...Show more |
SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter. |
3F5 FedoraprojectSuse5Fedora NginxStudio+2 moreApr 29, 2026 Dec 8, 2011 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via...Show more |
7Canonical DebianF5+4 more9Debian Linux FedoraLinux Enterprise+6 moreApr 29, 2026 Dec 6, 2010 N/A· v4 N/A· v3 4.3 MEDIUM· v2 OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to fo...Show more |