Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Big Ip Access Policy Manager HIGH 7.5
CVE-2015-8240

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM before 11.4.1 HF10, 11…

Mitigation only
Fix from $1,950 2016-04-11
Nginx MEDIUM 5.3
CVE-2016-0747EPSS 8%

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial …

Fix: 1.8.1 / 1.9.10+
Fix from $1,600 2016-02-15
Nginx CRITICAL 9.8
CVE-2016-0746EPSS 9%

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of servi…

Fix: 1.9.10 / 13.0+
Fix from $2,300 2016-02-15
Nginx HIGH 7.5
CVE-2016-0742EPSS 82%

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and work…

Fix: 1.8.1 / 1.9.10+
Fix from $1,950 2016-02-15
Big Iq Application Delivery Controller HIGH 7.5
CVE-2015-5516

Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3…

Mitigation only
Fix from $1,950 2016-01-20
Big Ip Domain Name System CRITICAL 9.8
CVE-2015-8611

BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, and PEM 12.0.0 before HF1 on the 2000, 4000, 5000, 7000, and 10000 platforms do not …

Mitigation only
Fix from $2,300 2016-01-12
Big Iq Application Delivery Controller HIGH 7.4
CVE-2015-7393

dcoep in BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.0 through 11.6.0 and 12.0.0 before 12.0.0 HF1, BIG-IP AAM 11.4.0 through 11.6.0 an…

Mitigation only
Fix from $1,950 2016-01-12
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2015-8098

F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or exe…

Mitigation only
Fix from $2,300 2016-01-12
Big Iq Security HIGH 9.0
CVE-2015-3628EPSS 68%

The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP A…

No fix yet
Fix from $1,950 2015-12-07
Big Iq Device HIGH 9.0
CVE-2015-7394

The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP A…

Mitigation only
Fix from $1,950 2015-11-06
Big Ip Application Acceleration Manager MEDIUM 6.1
CVE-2015-6546

The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and P…

Mitigation only
Fix from $1,600 2015-11-06
Big Ip Advanced Firewall Manager MEDIUM 5.0
CVE-2015-4638

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.…

Mitigation only
Fix from $1,600 2015-09-18
Big Ip Access Policy Manager HIGH 7.8
CVE-2015-5058

Memory leak in the virtual server component in F5 Big-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.5.x before 11.5.1 HF10,…

Mitigation only
Fix from $1,950 2015-08-24
Nginx MEDIUM 6.8
CVE-2014-3556EPSS 8%

The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not p…

Fix: 1.6.1 / 1.7.4+
Fix from $1,600 2014-12-29
Big Ip Local Traffic Manager MEDIUM 6.2
CVE-2014-8727

Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role t…

Fix: after 10.2.1
Fix from $1,600 2014-11-17
Big Ip Protocol Security Module MEDIUM 5.5
CVE-2014-6032

Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 a…

No fix yet
Fix from $1,600 2014-11-01
Big Ip Analytics HIGH 7.5
CVE-2013-7408

F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to have unspecified impact by gu…

No fix yet
Fix from $1,950 2014-10-26
Arx HIGH 9.3
CVE-2014-2927EPSS 8%

The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before HF7, 11.3.0 before HF9, and …

No fix yet
Fix from $1,950 2014-10-15
Arx Data Manager MEDIUM 6.5
CVE-2014-2949

SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL …

Mitigation only
Fix from $1,600 2014-06-18
Big Ip Webaccelerator HIGH 7.1
CVE-2014-2928EPSS 39%

The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through…

No fix yet
Fix from $1,950 2014-05-12
Big Iq HIGH 9.0
CVE-2014-3220EPSS 11%

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter i…

No fix yet
Fix from $1,950 2014-05-05
Nginx HIGH 7.5
CVE-2014-0088EPSS 9%

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers …

Patch available
Fix from $1,950 2014-04-29
Nginx HIGH 7.5
CVE-2014-0133EPSS 9%

Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitra…

Fix: 1.4.7+
Fix from $1,950 2014-03-28
Big Ip Webaccelerator HIGH 7.5
CVE-2012-3000

Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, P…

No fix yet
Fix from $1,950 2014-01-30
Nginx HIGH 7.5
CVE-2013-4547EPSS 68%

nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

Fix: 1.4.4+
Fix from $1,950 2013-11-23
Nginx HIGH 7.5
CVE-2013-0337

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, whic…

Fix: after 1.3.13
Fix from $1,950 2013-10-27
Big Ip Global Traffic Manager HIGH 7.8
CVE-2013-6016

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 through 10.2.2 and 11.0.0; An…

Mitigation only
Fix from $1,950 2013-10-26
Big Ip Access Policy Manager HIGH 9.3
CVE-2013-0150EPSS 6%

Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.…

Fix: after 11.3.0
Fix from $1,950 2013-08-09
Nginx MEDIUM 5.8
CVE-2013-2070EPSS 12%

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allow…

Fix: after 1.4.0
Fix from $1,600 2013-07-20
Nginx HIGH 7.5
CVE-2013-2028EPSS 87%

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash…

Fix: after 1.4.0
Fix from $1,950 2013-07-20