Vulnerability index

Browse CVEs

865 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Njs HIGH 7.5
CVE-2022-43284

Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. NOTE: the vendor disputes the…

Fix: after 0.7.4
Fix from $1,950 2022-10-28
Njs HIGH 7.5
CVE-2022-43285

Nginx NJS v0.7.4 was discovered to contain a segmentation violation in njs_promise_reaction_job. NOTE: the vendor disputes the significance of this r…

Patch available
Fix from $1,950 2022-10-28
F5os A HIGH 8.8
CVE-2022-41835

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.5.0, excessive file permissions in F5OS allows an authenticated local attacker to …

Fix: 1.1.0 / 1.5.0+
Fix from $1,950 2022-10-19
Big Ip Domain Name System HIGH 7.5
CVE-2022-41787

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when D…

Fix: 13.1.5.1 / 14.1.5.1+
Fix from $1,950 2022-10-19
Big Ip Advanced Firewall Manager HIGH 7.5
CVE-2022-41806

In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is…

Fix: 15.1.5.1 / 16.1.3.2+
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-41832

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a…

Fix: 13.1.5.1 / 14.1.5.1+
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-41833

In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause T…

Fix: after 13.1.5
Fix from $1,950 2022-10-19
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2022-41836

When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd proce…

Fix: 15.1.7 / 16.1.3.1+
Fix from $1,950 2022-10-19
Big Ip Advanced Firewall Manager MEDIUM 6.5
CVE-2022-41813

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or …

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,600 2022-10-19
F5os A MEDIUM 5.5
CVE-2022-41780

In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the …

Fix: 1.1.0 / 1.4.0+
Fix from $1,600 2022-10-19
Nginx HIGH 7.8
CVE-2022-41741

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R…

Fix: after 2.4.0
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-41624

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a s…

Fix: 13.1.5.1 / 14.1.5.2+
Fix from $1,950 2022-10-19
Big Ip Advanced Web Application Firewall HIGH 7.5
CVE-2022-41691

When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.

Fix: 14.1.5.2+
Fix from $1,950 2022-10-19
Big Ip Advanced Web Application Firewall HIGH 7.2
CVE-2022-41617

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the Advanced WAF / ASM module is…

Fix: 13.1.5.1 / 14.1.5.1+
Fix from $1,950 2022-10-19
Nginx HIGH 7.1
CVE-2022-41742

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R…

Fix: after 2.4.0
Fix from $1,950 2022-10-19
Nginx Ingress Controller HIGH 7.0
CVE-2022-41743

NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGIN…

Fix: after 2.4.0
Fix from $1,950 2022-10-19
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-41770

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-…

Fix: 14.1.5.1 / 15.1.7+
Fix from $1,600 2022-10-19
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-36795

In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, when an LTM TCP profile with Aut…

Fix: 14.1.5.1 / 15.1.7+
Fix from $1,950 2022-10-19
Njs MEDIUM 5.5
CVE-2022-38890

Nginx NJS v0.7.7 was discovered to contain a segmentation violation via njs_utf8_next at src/njs_utf8.h

Patch available
Fix from $1,600 2022-09-15
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2022-35728

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BI…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $2,300 2022-08-04
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-34865

In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds, which use HTTPS, do not veri…

Fix: 14.1.5 / 15.1.6.1+
Fix from $2,300 2022-08-04
Big Ip Access Policy Manager CRITICAL 9.1
CVE-2022-35243

In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when running in Appliance mode, an…

Fix: 14.1.5 / 15.1.6.1+
Fix from $2,300 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34651

In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on …

Fix: 15.1.6.1 / 16.1.3.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34655

In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is co…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34844

In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elas…

Fix: 15.1.6.1 / 16.1.3.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-34862

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is co…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-35236

In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server,…

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-35240

In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry …

Fix: 14.1.5 / 15.1.6.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.5
CVE-2022-35245

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a vir…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $1,950 2022-08-04
Big Ip Access Policy Manager HIGH 7.2
CVE-2022-35735

In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with…

Fix: 14.1.5.1 / 15.1.6.1+
Fix from $1,950 2022-08-04