Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2015-1050

Published Jan 15, 2015

Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Respons…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3556

Published Dec 29, 2014

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9342

Published Dec 8, 2014

Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3616

Published Dec 8, 2014

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, wh…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8727

Published Nov 17, 2014

Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitra…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7408

Published Oct 26, 2014

F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by guessing the value.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2949

Published Jun 18, 2014

SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vecto…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2928

Published May 12, 2014

The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11…

CVSS 7.1 · High

CVE-2014-3220

Published May 5, 2014

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0088

Published Apr 29, 2014

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0133

Published Mar 28, 2014

Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-3000

Published Jan 30, 2014

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Ana…

CVSS 7.5 · High

CVE-2012-2997

Published Jan 21, 2014

XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to r…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,024 CVEsPage 39 of 41