Skip to main content

Vendor archive

f5 CVEs

Beta · best-effort

1,024 CVEs tagged to vendor f575 Critical, 562 High, 372 Medium, 15 Low, 0 Unrated.

CVE-2008-7032

Published Aug 24, 2009

Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hijack the authentication of adm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2119

Published Jun 18, 2009

Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject ar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6474

Published Mar 16, 2009

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3149

Published Jul 11, 2008

The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstalled OID branch in HOST-RESOURCE…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2637

Published Jun 10, 2008

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2030

Published Apr 30, 2008

Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1503

Published Mar 25, 2008

Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a no…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6704

Published Mar 5, 2008

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attac…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6258

Published Feb 19, 2008

Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers to execute arbitrary code via a long (1) Host header, or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0539

Published Feb 1, 2008

Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0265

Published Jan 15, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5979

Published Nov 15, 2007

Cross-site scripting (XSS) vulnerability in download_plugin.php3 in F5 Firepass 4100 SSL VPN 5.4 through 5.5.2 and 6.0 through 6.0.1 allows remote attackers to inject arbitrary we…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3097

Published Jun 6, 2007

my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0186

Published Jan 12, 2007

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the xcho parameter to my.logon.php…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0187

Published Jan 12, 2007

F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (3) Unicode encoding, (4) URL-e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0188

Published Jan 12, 2007

F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP address ("dotless IP address")…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0195

Published Jan 12, 2007

my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than for those with an invalid userna…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5416

Published Oct 20, 2006

Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5 Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows remote attackers to inject arbitrary web script o…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3550

Published Jul 13, 2006

Multiple cross-site scripting (XSS) vulnerabilities in F5 Networks FirePass 4100 5.x allow remote attackers to inject arbitrary web script or HTML via unspecified "writable form f…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1357

Published Mar 22, 2006

Cross-site scripting (XSS) vulnerability in my.support.php3 in F5 Firepass 4100 SSL VPN 5.4.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2245

Published Jul 12, 2005

Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ci…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-1999-1550

Published Nov 8, 1999

bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,001-1,024 of 1,024 CVEsPage 41 of 41