Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2013-0337

Published Oct 27, 2013

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, which allows local users to obtain…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6016

Published Oct 26, 2013

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; Analytics 11.0.0; PSM 9.4.0 thro…

CVSS 7.8 · High

CVE-2013-5976

Published Oct 1, 2013

Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5975

Published Oct 1, 2013

The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2070

Published Jul 20, 2013

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2028

Published Jul 20, 2013

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2975

Published Sep 11, 2012

Cross-site scripting (XSS) vulnerability in the traffic overview page on the F5 ASM appliance 10.0.0 through 11.2.0 HF2 allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4963

Published Jul 26, 2012

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files via (1) a trailing . (dot) or (2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2089

Published Apr 17, 2012

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote at…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2053

Published Apr 5, 2012

The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as root, which allows local user…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1777

Published Apr 5, 2012

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL commands via the state parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2266

Published Jun 15, 2010

nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2263

Published Jun 15, 2010

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4487

Published Jan 13, 2010

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary co…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3898

Published Nov 24, 2009

Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to cr…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3896

Published Nov 24, 2009

src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attack…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,024 CVEsPage 40 of 41