Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nginx MEDIUM 5.0
CVE-2011-4963EPSS 6%

nginx/Windows 1.3.x before 1.3.1 and 1.2.x before 1.2.1 allows remote attackers to bypass intended access restrictions and access restricted files vi…

Fix: 1.2.1+
Fix from $1,600 2012-07-26
Big Ip Application Security Manager HIGH 7.8
CVE-2012-1493EPSS 63%

F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before …

Patch available
Fix from $1,950 2012-07-09
Nginx MEDIUM 6.8
CVE-2012-2089EPSS 10%

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 direc…

Fix: after 1.1.18
Fix from $1,600 2012-04-17
Nginx MEDIUM 5.0
CVE-2012-1180EPSS 10%

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process m…

Fix: 1.0.14 / 1.1.17+
Fix from $1,600 2012-04-17
Firepass HIGH 7.5
CVE-2012-1777

SQL injection vulnerability in my.activation.php3 in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 allows remote attackers to execute arbitrary SQL comma…

No fix yet
Fix from $1,950 2012-04-05
Firepass HIGH 7.2
CVE-2012-2053

The sudoers file in the Linux system configuration in F5 FirePass 6.0.0 through 6.1.0 and 7.0.0 does not require a password for executing commands as…

No fix yet
Fix from $1,950 2012-04-05
Nginx MEDIUM 6.8
CVE-2011-4315EPSS 6%

Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial …

Fix: 1.0.10+
Fix from $1,600 2011-12-08
Nginx MEDIUM 5.0
CVE-2010-2263EPSS 72%

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrar…

Fix: 0.7.66+
Fix from $1,600 2010-06-15
Nginx MEDIUM 5.0
CVE-2010-2266EPSS 22%

nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corru…

Fix: 0.7.67+
Fix from $1,600 2010-06-15
Nginx MEDIUM 6.8
CVE-2009-4487EPSS 30%

nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or…

Patch available
Fix from $1,600 2010-01-13
Big Ip Protocol Security Module HIGH 7.8
CVE-2009-4420

Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0 through 10.0.1, and Protocol…

Mitigation only
Fix from $1,950 2009-12-24
Nginx MEDIUM 5.0
CVE-2009-3896EPSS 10%

src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x befo…

Patch available
Fix from $1,600 2009-11-24
Nginx HIGH 7.5
CVE-2009-2629EPSS 75%

Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows…

Fix: 0.5.38 / 0.6.39+
Fix from $1,950 2009-09-15
Big Ip MEDIUM 6.8
CVE-2008-7032

Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3 allows remote attackers to hi…

No fix yet
Fix from $1,600 2009-08-24
Tmos HIGH 9.0
CVE-2008-6474

The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unsp…

Mitigation only
Fix from $1,950 2009-03-16
Firepass 1200 HIGH 7.8
CVE-2008-3149

The SNMP daemon in the F5 FirePass 1200 6.0.2 hotfix 3 allows remote attackers to cause a denial of service (daemon crash) by walking the hrSWInstall…

Mitigation only
Fix from $1,950 2008-07-11
Firepass 4100 HIGH 7.5
CVE-2007-3097

my.activation.php3 in F5 FirePass 4100 SSL VPN allows remote attackers to execute arbitrary shell commands via shell metacharacters in the username p…

Patch available
Fix from $1,950 2007-06-06
Firepass HIGH 7.5
CVE-2007-0187

F5 FirePass 5.4 through 5.5.2 and 6.0 allows remote attackers to access restricted URLs via (1) a trailing null byte, (2) multiple leading slashes, (…

Mitigation only
Fix from $1,950 2007-01-12
Firepass 4100 MEDIUM 6.8
CVE-2007-0186

Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN allow remote attackers to inject arbitrary web script or HTML via (1) the …

Mitigation only
Fix from $1,600 2007-01-12
Firepass MEDIUM 6.5
CVE-2007-0188

F5 FirePass 5.4 through 5.5.1 does not properly enforce host access restrictions when a client uses a single integer (dword) representation of an IP …

Mitigation only
Fix from $1,600 2007-01-12
Firepass MEDIUM 5.0
CVE-2007-0195

my.activation.php3 in F5 FirePass 5.4 through 5.5.1 and 6.0 displays different error messages for failed login attempts with a valid username than fo…

Mitigation only
Fix from $1,600 2007-01-12
Firepass 1000 MEDIUM 5.1
CVE-2006-5416

Cross-site scripting (XSS) vulnerability in my.acctab.php3 in F5 Networks FirePass 1000 SSL VPN 5.5, and possibly earlier, allows remote attackers to…

Patch available
Fix from $1,600 2006-10-20
Tmos HIGH 7.5
CVE-2005-2245

Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors…

Patch available
Fix from $1,950 2005-07-12
Icontrol Service Manager HIGH 7.5
CVE-2004-1307EPSS 6%

Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF …

Patch available
Fix from $1,950 2004-12-21
Tmos MEDIUM 5.0
CVE-1999-1550EPSS 9%

bigconf.conf in F5 BIG/ip 2.1.2 and earlier allows remote attackers to read arbitrary files by specifying the target file in the "file" parameter.

Mitigation only
Fix from $1,600 1999-11-08